medium · CVSS v3 6.4 · EPSS 0.00162
CVE-2026-89303
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in…
Description
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 6.4
- CVSS v4
- —
- EPSS
- 0.00162