External risk intelligence

JNews Pay Writer SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96328

This vulnerability affects a WordPress plugin, which is a type of web application component. WordPress sites are frequently deployed as public-facing web applications, making this plugin's functionality exposed to internet users by default in typical website configurations.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the JNews - Pay Writer component, which could allow attackers to inject malicious SQL commands into your systems. This type of attack, known as SQL injection, can potentially lead to unauthorized access to sensitive data. The main concern is to confirm if this component is in use and assess the potential exposure.

  • An SQL injection flaw allows unauthorized data access.
  • Critical vulnerability affects widely used web components.
  • Confirm usage and assess potential exposure to data.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to a website using the JNews - Pay Writer plugin. This could allow them to infer information from the database, potentially leading to unauthorized access or data leakage.

  • No authentication or user interaction needed.
  • Triggered by sending malicious SQL commands.
  • Allows for blind SQL injection attacks.

Live Threat

Current exploitation, exposure, and threat context

A SQL injection vulnerability in the JNews - Pay Writer plugin could allow an unauthenticated attacker to perform a blind SQL injection when supported by the advisory's conditions. This means an attacker might be able to infer information about the underlying database by observing the application's responses to carefully crafted queries, without direct access to the database or administrative privileges.

  • Database content could be exfiltrated.
  • Malicious SQL queries could be injected.
  • Sensitive data may be exposed.

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in the JNews - Pay Writer plugin requires immediate attention from teams managing WordPress instances and the specific plugin. The first step is to identify all deployments of the affected plugin, determine their internet reachability, and assess their business criticality. Once identified, the accountable owner for each instance should be located to plan appropriate remediation, which may involve vendor coordination for a fix or implementing temporary risk reduction measures.

  • Plugin owners should manage this vulnerability.
  • Verify plugin reachability and business criticality.
  • Plan remediation based on exposure and risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the JNews - Pay Writer plugin?

JNews - Pay Writer is a WordPress plugin designed to facilitate payments for content contributors or writers on a website. It operates within the WordPress ecosystem to handle financial interactions related to article submissions. Like other plugins, it extends site functionality by managing data stored in the WordPress database, which makes it a specific point of integration between public web traffic and back-end information.

What does CVE-2026-96328 mean for data security?

This vulnerability is classified as CWE-89, or SQL Injection. In plain terms, it means the plugin fails to properly filter malicious input sent to the database. Because it is a 'Blind' SQL injection, an attacker cannot see the database content directly, but they can reconstruct information by asking the database true-or-false questions and observing how the website responds, effectively leaking data piece by piece.

How is this vulnerability triggered?

An attacker triggers this by sending specifically crafted, malicious web requests to the site. Importantly, the vulnerability does not require the attacker to have an existing account, administrative rights, or any form of login. It also does not rely on a specific user clicking a link; the flaw exists within the plugin's code, meaning any network-based request designed to exploit the flaw can initiate the process.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because this is a WordPress plugin, it is often part of a public-facing web application. Since these components are typically designed to be reachable by internet users by default, your instance is likely exposed if the plugin is installed and active on a site accessible to the public internet.

What should I do if I use this plugin?

Start by auditing your WordPress environments to identify every installation where JNews - Pay Writer is active. Once identified, evaluate whether each site is internet-facing or internal to understand the scope of potential access. After assessing the business criticality of those specific sites, coordinate with your technical team to track the vendor for a security update or implement temporary measures to protect your database.

References