medium · CVSS v3 6.8 · EPSS 0.00177
CVE-2026-93000
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its …
Description
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
Scores
- Severity
- medium
- CVSS v2
- 5.4
- CVSS v3
- 6.8
- CVSS v4
- —
- EPSS
- 0.00177