cleantalk
Vulnerabilities and Security Researches

Bluff Post, CVE-2026-89237

CVE, Research URL

CVE-2026-89237

Application

Bluff Post

Published on
Sep 26, 2026
Research Description
The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.
Affected versions
max 1.1.1.
Status
vulnerable