SPS-Suite, CVE-2026-93000
- CVE, Research URL
- Home page URL
- Application
- Published on
- Sep 28, 2026
- Research Description
- The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
- Affected versions
-
max 1.4.0.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| SPS-Suite (CVE-2026-93000) , Sep 30, 2026 |