HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-56036Published Modified CNA Patchstack

CVE-2026-56036: WordPress 워드프레스 결제 심플페이 plugin <= 5.5.6 - SQL Injection vulnerability

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

Metrics

CVSS v3.1
9.3
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An unauthenticated SQL injection vulnerability affects the WordPress plugin 워드프레스 결제 심플페이 (WordPress Payment SimplePay by codemstory) at version 5.5.6 and earlier. The flaw is reachable over the network with no credentials required, making it exploitable by any party that can send HTTP requests to a WordPress site running the plugin. Successful exploitation gives an attacker read access to the underlying database and causes limited disruption to service availability. No fix version has been published yet; HarborGuard is tracking the advisory and will surface a patched rebuild as soon as upstream ships one.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from Patchstack and other upstream advisory feeds within minutes of publication and matched against customer images, including custom-built WordPress images that bundle this plugin. Any image found to carry an affected version of 워드프레스 결제 심플페이 at or below 5.5.6 is flagged immediately.

Available
Triage

HarborGuard scores this vulnerability at CVSS 9.3 Critical and is capable of weighting that score against each customer organization's compliance policy to determine escalation priority. Triage results are routed to the appropriate team inbox within each customer environment based on configured ownership rules.

Available
Patch

Because no upstream fix version has been published, HarborGuard re-evaluates this advisory on every ingest cycle and will make a patched-image rebuild available the moment a remediated version is released. For customers who have opted into auto-remediation, the rebuild, regression run, and PR against affected workloads will trigger automatically once an upstream fix exists.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The vulnerable plugin endpoint is exposed over the network, so an attacker must be able to send HTTP requests to the WordPress site to reach it.

  • AuthenticationNot required

    No account or session token of any kind is needed; the injection point is accessible to unauthenticated requests.

  • Victim interactionNot required

    The attacker sends crafted requests directly to the server; no user action or social-engineering step is required.

  • Attack complexityDetail

    Exploit conditions are straightforward and reliable, with no race conditions, special configurations, or environmental factors required to trigger the injection.

Blast Radius

  • An attacker reads arbitrary rows from the WordPress database, including stored user credentials, session tokens, private post content, and plugin configuration data.
  • Database contents from other applications sharing the same database server may be accessible depending on the MySQL user's granted privileges, because the CVSS scope is marked Changed.
  • The affected service experiences limited availability impact, meaning targeted queries or repeated exploitation may degrade database responsiveness for legitimate users.

How HarborGuard Handles This

Available on HarborGuard: this CVE is matched against all customer images carrying the 워드프레스 결제 심플페이 plugin at version 5.5.6 or below, scored at CVSS 9.3 Critical, and surfaced for immediate triage. Because no upstream fix exists today, HarborGuard monitors the Patchstack advisory and the codemstory plugin repository on every ingest cycle. Where compliance policy permits, compensating controls can be documented in HarborGuard's policy layer, including network-policy rules that restrict public access to affected WordPress endpoints, web-application firewall rule suggestions, and feature-flag or plugin-deactivation guidance. The moment an upstream patch is published, a patched-image rebuild becomes available, and for customers with auto-remediation enabled, HarborGuard opens a PR against affected workloads with a regression test run attached, with a typical median time from CVE patch publication to merged PR of around 90 minutes for Critical-severity issues in auto-remediation environments.

See how HarborGuard automates this
Affected packages
  • codemstory / 워드프레스 결제 심플페이
    ≤ 5.5.6
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
References