CVE-2026-93368 Overview
CVE-2026-93368 is a time-based SQL injection vulnerability in the Rename wp-login.php to anything you want plugin for WordPress. All versions up to and including 2.0.1 are affected. The flaw exists in the plugin's handling of the log (username) POST parameter during failed login processing. Unauthenticated attackers can inject SQL clauses into an existing query to extract sensitive database contents. WordPress core applies wp_unslash() to the log value before dispatching the wp_login_failed action, which strips magic-quotes escaping and allows a raw single quote to reach the plugin's handler.
Critical Impact
Unauthenticated attackers can extract sensitive information, including credential hashes and session tokens, from the WordPress database via time-based blind SQL injection.
Affected Products
- Rename wp-login.php to anything you want plugin for WordPress — all versions through 2.0.1
- WordPress sites exposing the standard login endpoint with the vulnerable plugin active
- Any hosting environment where the plugin processes the wp_login_failed action
Discovery Timeline
- 2026-09-23 - CVE-2026-93368 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-93368
Vulnerability Analysis
The vulnerability is a classified [CWE-89] SQL injection defect residing in the plugin's failed-login handler. The plugin consumes the log POST parameter (submitted username) and concatenates it into a SQL query without adequate escaping or parameter binding via wpdb::prepare(). Because the query executes against the WordPress database, an attacker can append conditional time-delay payloads such as SLEEP() expressions to infer data one bit at a time. Extraction targets typically include the wp_users table containing password hashes and email addresses. The attack does not require authentication and is reachable over the network through the standard login POST endpoint.
Root Cause
The plugin performs insufficient escaping on the user-supplied log value and lacks proper statement preparation on the surrounding SQL query. WordPress core calls wp_unslash() on the log POST value before dispatching the wp_login_failed action. That call removes the magic-quotes backslash escaping WordPress normally adds, so a raw single quote reaches the plugin's handler and breaks out of the string literal in the concatenated query.
Attack Vector
An unauthenticated attacker submits a crafted login POST request in which the log parameter contains a boolean or time-based SQL payload. When authentication fails, the plugin's wp_login_failed hook processes the tainted value and executes the injected SQL. Response timing differences reveal whether injected predicates evaluated true, enabling blind exfiltration of arbitrary column values. Refer to the Wordfence Vulnerability Report and the WordPress Plugin Code Snippet for the vulnerable handler.
Detection Methods for CVE-2026-93368
Indicators of Compromise
- POST requests to wp-login.php or the renamed login slug containing SQL keywords such as SLEEP, BENCHMARK, SELECT, UNION, or single quotes in the log field.
- Unusually long response times on failed login attempts, often clustered around multiples of the injected delay value.
- Repeated failed login events from a single source IP with varying, non-human log parameter values.
- Web server or database logs showing malformed SQL fragments originating from the plugin's failed-login code path.
Detection Strategies
- Deploy web application firewall rules that block SQL metacharacters and time-delay functions in the log POST parameter.
- Correlate authentication failure events with anomalous request latency to surface blind injection attempts.
- Enable MySQL slow query logs and alert on statements originating from the plugin file init.php.
Monitoring Recommendations
- Ingest WordPress access logs and MySQL query logs into a centralized analytics platform for correlated review.
- Track baseline response times on wp-login.php and alert on statistical deviations that indicate SLEEP()-based probing.
- Monitor the wp_users and wp_options tables for unexpected read patterns from unauthenticated sessions.
How to Mitigate CVE-2026-93368
Immediate Actions Required
- Deactivate and remove the Rename wp-login.php to anything you want plugin until a patched release becomes available.
- Enforce WAF or reverse-proxy rules that reject log parameter values containing SQL syntax or excessive length.
- Rotate all WordPress user passwords and administrative session tokens if injection activity is suspected.
- Audit the wp_users table for unauthorized account creation or privilege changes.
Patch Information
No fixed version is identified in the referenced advisory at publication. Site operators should track the Wordfence Vulnerability Report and the plugin's source repository for a release that replaces string concatenation with wpdb::prepare() calls.
Workarounds
- Restrict access to the login endpoint by source IP or via HTTP basic authentication at the web server layer.
- Apply rate limiting and CAPTCHA on failed login attempts to slow blind extraction.
- Replace the plugin with a maintained alternative that uses parameterized queries for handling authentication input.
# Configuration example: NGINX rule to block SQL keywords in the log parameter
location = /wp-login.php {
if ($request_method = POST) {
set $block 0;
if ($request_body ~* "log=[^&]*(select|union|sleep|benchmark|--|')") {
set $block 1;
}
if ($block = 1) { return 403; }
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
