{"id":"CVE-2026-93000","published":"2026-09-28T07:17:21.613","lastModified":"2026-09-28T16:38:58.950","description":"The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.","cvssScore":6.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/a6f90424-46df-4f44-9491-76c75b5ab5eb/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}