rootpwn

medium · CVSS v3 6.4 · EPSS 0.00162

CVE-2026-89303

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in…

Description

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
6.4
CVSS v4
—
EPSS
0.00162

← All CVEs