400,000 WordPress Sites Affected by Unauthenticated SQL Injection Vulnerability in Ally WordPress Plugin

Date:

Security Update for WordPress

Security Alert: SQL Injection Vulnerability in Ally Plugin

On February 4, 2026, a serious SQL Injection vulnerability was found in the Ally WordPress plugin, which has over 400,000 active users. This flaw allows attackers to access sensitive information from the database, including password hashes.

The vulnerability was discovered by Drew Webber and reported through the Wordfence Bug Bounty Program. It was quickly addressed, with a patch released on February 23, 2026. Users of Ally versions 4.0.3 and earlier are at risk and should update to version 4.1.0 immediately to protect their sites.

All Wordfence users, including those on the free version, are safeguarded against this threat. If you use the Ally plugin, please ensure your site is updated to stay secure.

Why This Matters

This issue may affect your WordPress website if you are using the mentioned plugin or theme. You should fix this as soon as possible to avoid security risks.

Recommended Fix

  • Install the latest version of the affected plugin
  • Remove unnecessary plugins
  • Scan your website for malware
  • Ensure WordPress is up to date

Security Risk

This vulnerability could allow attackers to exploit your site.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...