Security Update for WordPress
Security Alert: SQL Injection Vulnerability in Ally Plugin
On February 4, 2026, a serious SQL Injection vulnerability was found in the Ally WordPress plugin, which has over 400,000 active users. This flaw allows attackers to access sensitive information from the database, including password hashes.
The vulnerability was discovered by Drew Webber and reported through the Wordfence Bug Bounty Program. It was quickly addressed, with a patch released on February 23, 2026. Users of Ally versions 4.0.3 and earlier are at risk and should update to version 4.1.0 immediately to protect their sites.
All Wordfence users, including those on the free version, are safeguarded against this threat. If you use the Ally plugin, please ensure your site is updated to stay secure.
Why This Matters
This issue may affect your WordPress website if you are using the mentioned plugin or theme. You should fix this as soon as possible to avoid security risks.
Recommended Fix
- Install the latest version of the affected plugin
- Remove unnecessary plugins
- Scan your website for malware
- Ensure WordPress is up to date
Security Risk
This vulnerability could allow attackers to exploit your site.
Source: View Original Report
