rootpwn

medium · CVSS v3 6.8 · EPSS 0.00177

CVE-2026-93000

The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its …

Description

The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.

Scores

Severity
medium
CVSS v2
5.4
CVSS v3
6.8
CVSS v4
—
EPSS
0.00177

← All CVEs