CVE-2026-2495 | WPNakama Plugin up to 0.6.5 on WordPress REST API Endpoint boards order sql injection
A vulnerability was found in WPNakama Plugin up to 0.6.5 on WordPress. It has been rated as critical. This vulnerability affects unknown code of the file /wp-json/WPNakama/v1/boards of the component REST API Endpoint. Performing a manipulation of the argument order results in sql injection.
This vulnerability is reported as CVE-2026-2495. The attack is possible to be carried out remotely. No exploit exists.