CVE-2026-88930
Received Received - Intake

SQL Injection in Social Web Suite WordPress Plugin

Vulnerability report for CVE-2026-88930, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Social Web Suite 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-88930 is an unauthenticated blind SQL injection vulnerability in the Social Web Suite WordPress plugin versions up to 4.1.12. The plugin fails to require a shared secret for authorization and does not sanitize or escape a parameter used in an SQL query, allowing attackers to execute SQL injection attacks without authentication.

Detection Guidance

To detect this vulnerability, check if the Social Web Suite WordPress plugin version is 4.1.12 or lower. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details. Look for unauthorized SQL queries or unusual database activity.

Impact Analysis

This vulnerability allows unauthenticated attackers to perform SQL injection attacks, which can lead to unauthorized data access, manipulation, or deletion in the WordPress database. It may also enable attackers to take control of the website or extract sensitive information.

Compliance Impact

This vulnerability could lead to data breaches, violating compliance requirements such as GDPR (data protection) and HIPAA (health information security). Unauthorized access to sensitive data may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Immediately update the Social Web Suite plugin to the latest version beyond 4.1.12. Ensure the shared secret is properly configured and enable input sanitization. Monitor database logs for suspicious queries and restrict access to the plugin's admin interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88930. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart