OVERVIEW CVE-2026-3773 is a SQL Injection vulnerability in the Accessibility Suite by Ability, Inc WordPress plugin affecting all versions through 4.20. The flaw exists in the 'scan_id' parameter due to insufficient input escaping and improper SQL query preparation, allowing attackers to inject arbitrary SQL commands into database queries. SEVERITY The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector requiring low complexity and low privileges. Authenticated users with Subscriber-level access or higher can exploit this flaw, and successful exploitation enables unauthorized extraction of sensitive database information. The attack requires no user interaction, making it straightforward for malicious insiders to execute once authenticated. EXPLOITATION STATUS This vulnerability is currently not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no indicators of active exploitation in the wild. The extremely low EPSS score of 0.0001 and inactive status on threat intelligence hot lists suggest minimal current exploitation activity. However, given the relative simplicity of SQL Injection attacks and the low barrier to entry for authenticated users, organizations should prioritize patching to version 4.21 or later to mitigate risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Onlineada | Accessibility Suite By Ability, Inc | >= 0, <= 4.20CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.