CVE-2026-57756: Contributor SQL Injection in nicen-localize-image Vulnerability.

Release Date: 6th July 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

A SQL Injection vulnerability affecting the nicen-localize-image WordPress plugin, versions 1.4.9 and earlier. This is classified as a "Contributor" level vulnerability — meaning it requires an authenticated user with at least Contributor-role privileges (WordPress's lowest privileged content-creation role) to exploit, rather than being reachable by a fully unauthenticated attacker.

 

References

  1. https://www.cisa.gov/news-events/bulletins/sb26-187
  2. https://www.cve.org/CVERecord?id=CVE-2026-57756