{"id":"CVE-2026-89303","published":"2026-09-28T07:17:21.283","lastModified":"2026-09-28T16:38:58.950","description":"The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.","cvssScore":6.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/dbe62e96-6493-4385-92a2-6281c5428a9f/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}