Security Digest: June 13, 2026 - 4 Critical Vulnerabilities

Today’s alerts are dominated by two SQL injection flaws and two WordPress XSS issues that can expose sensitive data, hijack sessions, and in one case enable persistent script execution through a public API path. The immediate priority is to patch exposed systems now, then verify whether any affected plugins or Koha deployments are in production and accessible to untrusted users.

· 8 min read

Security Digest: June 13, 2026 — 4 High-Risk Vulnerabilities Demanding Immediate Action

Executive Summary

Today’s alerts are dominated by two SQL injection flaws and two WordPress XSS issues that can expose sensitive data, hijack sessions, and in one case enable persistent script execution through a public API path. The immediate priority is to patch exposed systems now, then verify whether any affected plugins or Koha deployments are in production and accessible to untrusted users.

Teams running Koha or WordPress should treat these as active-risk issues: one flaw can leak database contents from authenticated staff accounts, while the WordPress issues can be exploited by unauthenticated attackers in common site configurations.

Critical Vulnerabilities

CVE-2026-6428: Koha Reports SQL Injection in reports/catalogue_out.pl

Impact: An authenticated staff user with the Reports module flag can read arbitrary data from the Koha application database. That includes borrower records, password hashes, 2FA secrets, API keys, recovery data, and active sessions.

Affected Systems: Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00.

Immediate Action: Patch immediately if you run any affected Koha branch. Restrict Reports module access to only trusted staff until upgrades are complete, and review logs for suspicious requests to catalogue_out.pl.

Mitigation: Upgrade to the fixed releases: 22.11.38, 24.11.16, 25.05.11, 25.11.05, 26.05.01, or 26.11.00. If immediate patching is not possible, remove or tightly limit the Reports module flag for non-essential users.

CVE-2026-9848: WP Ticket SQL Injection via WordPress Search Parameter

Impact: An unauthenticated attacker can inject SQL through the public search parameter and potentially extract sensitive database information.

Affected Systems: WP Ticket plugin for WordPress versions up to and including 6.0.4.

Immediate Action: Disable or remove the plugin now if you do not need it. If it must remain online, block public search abuse at the edge and move to the vendor-fixed version as soon as it is available.

Mitigation: Apply the patched release from the vendor, or temporarily deactivate the plugin on internet-facing sites. Review database and application logs for unusual search requests containing SQL syntax or long, malformed query strings.

CVE-2026-9109: GPTranslate Stored XSS via REST API Translation Storage

Impact: Attackers can store malicious scripts that execute when users view affected pages. Because the API key is exposed in page source, unauthenticated attackers can submit payloads without additional preconditions.

Affected Systems: GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites versions up to and including 2.31.

Immediate Action: Update or disable the plugin immediately. Treat any site using this plugin as potentially exposed, especially if translations are accepted or refreshed automatically.

Mitigation: Upgrade to the vendor-fixed version once available. Clear cached pages, review translated content for injected scripts, and rotate any exposed credentials or API-related secrets if you suspect abuse.

CVE-2026-5513: Bookly Stored XSS via bookly-customer-full-name Cookie

Impact: An attacker can inject scripts that run in a victim’s browser when they later visit an affected page. This can lead to session theft, account actions, or phishing inside the site.

Affected Systems: Online Scheduling and Appointment Booking System – Bookly plugin for WordPress versions up to and including 27.2, only when the Remember personal information in cookies setting is enabled.

Immediate Action: Disable the cookie-based personal information setting now if it is enabled, then patch the plugin. Assume any public booking flow may be abused if the site is unpatched.

Mitigation: Update to the fixed version from the vendor. If you cannot patch immediately, turn off the affected setting, clear cookies, and inspect pages that render customer names for stored script content.

Previously Alerted

What to Do Now

  1. Patch or disable exposed products today: Koha, WP Ticket, GPTranslate, and Bookly should be treated as urgent maintenance items.
  2. Reduce attack surface: remove unused plugins, restrict Koha Reports access, and disable risky WordPress features such as public search or cookie-based storage where possible.
  3. Check for compromise: review recent SQL errors, unusual search requests, unexpected translation changes, and suspicious booking form activity.
  4. Rotate secrets if exposure is suspected: API keys, session data, and any credentials that may have been stored in affected databases.

Verification steps:

  • Confirm installed versions against the affected ranges listed above.
  • Check whether the Koha Reports module is enabled for broad staff access.
  • Inspect WordPress plugin inventories on all public sites, including staging environments that may still be reachable.

Monitoring recommendations:

  • Alert on repeated requests to catalogue_out.pl or search queries containing SQL operators, comments, or encoded payloads.
  • Watch for unexpected changes in translated page content, injected scripts, or new admin sessions.
  • Review web server and application logs for spikes in 500 errors, database exceptions, and atypical cookie values.

Related Resources

  • Internal blog posts: Security team guidance on emergency patch validation, WordPress plugin triage, and Koha hardening (to be published).
  • Official vendor advisories: Koha release notes and security announcements; WP Ticket, GPTranslate, and Bookly vendor security advisories and patch notes.

Keep reading