SQL injection in the Ally WordPress plugin affects over 200,000 sites

Wordfence reports that a critical SQL injection flaw in the Ally WordPress plugin, tracked as CVE-2026-2413, is being used to attack websites. The plugin failed to filter user input in URL parameters, letting an attacker run database queries without logging in. That can expose administrator accounts, email addresses and password hashes. A fix arrived in version 4.1.0 on 23 February, but around 60 percent of installations were still unpatched on 11 March.

What this means for your business

For many organisations the website is outsourced to an agency and then forgotten, while it still handles personal data from forms and newsletter sign-ups. A flaw that is easy to automate gets exploited at scale, not because anyone singled you out, but because you are on a list. If password hashes and email addresses are extracted, this is a personal data breach with notification obligations.

Berigo recommends

  • Update Ally to version 4.1.0 or later immediately and verify the update is actually installed.
  • Review access logs from 23 February onwards for unusual queries against URL parameters.
  • Reset passwords for all administrator accounts and enable multi-factor authentication on the site's admin.
  • Agree in writing with the agency running your site who follows up security updates, and within what deadline.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch