cleantalk
Vulnerabilities and Security Researches

SPS-Suite, CVE-2026-93000

CVE, Research URL

CVE-2026-93000

Application

SPS-Suite

Published on
Sep 28, 2026
Research Description
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
Affected versions
max 1.4.0.
Status
vulnerable