CVE-2026-22850 | ibericode koko-analytics Plugin up to 2.1.2 on WordPress Public Tracking Endpoint Data_Export.php pa/r sql injection (GHSA-jgfh-264m-xh3q)
A vulnerability was found in ibericode koko-analytics Plugin up to 2.1.2 on WordPress. It has been rated as critical. This affects an unknown function of the file src/Admin/Data_Export.php of the component Public Tracking Endpoint. The manipulation of the argument pa/r leads to sql injection.
This vulnerability is traded as CVE-2026-22850. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.