400,000 WordPress Sites Affected by Unauthenticated SQL Injection Vulnerability in Ally WordPress Plugin

Date:

Security Update for WordPress

Security Alert: SQL Injection Vulnerability in Ally Plugin

On February 4, 2026, a serious SQL Injection vulnerability was found in the Ally WordPress plugin, which has over 400,000 active users. This flaw allows attackers to access sensitive information from the database, including password hashes.

The vulnerability was discovered by Drew Webber and reported through the Wordfence Bug Bounty Program. It was quickly addressed, with a patch released on February 23, 2026. Users of Ally versions 4.0.3 and earlier are at risk and should update to version 4.1.0 immediately to protect their sites.

All Wordfence users, including those on the free version, are safeguarded against this threat. If you use the Ally plugin, please ensure your site is updated to stay secure.

Why This Matters

This issue may affect your WordPress website if you are using the mentioned plugin or theme. You should fix this as soon as possible to avoid security risks.

Recommended Fix

  • Install the latest version of the affected plugin
  • Remove unnecessary plugins
  • Scan your website for malware
  • Ensure WordPress is up to date

Security Risk

This vulnerability could allow attackers to exploit your site.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...