CVE-2026-93000 - SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search
CVE ID :CVE-2026-93000
Published : Sept. 28, 2026, 6 a.m. | 1 hour, 12 minutes ago
Description :The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 28, 2026, 6 a.m. | 1 hour, 12 minutes ago
Description :The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...