CVE-2026-89195
Received Received - Intake

SQL Injection in Site Setup Wizard WordPress Plugin

Vulnerability report for CVE-2026-89195, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Site Setup Wizard 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Site Setup Wizard WordPress plugin through version 1.5.8 has an unauthenticated SQL injection vulnerability. It fails to properly sanitize and escape a parameter used in SQL queries, allowing attackers to inject malicious SQL code and read sensitive database data without authentication.

Detection Guidance

To detect this vulnerability, check if the Site Setup Wizard WordPress plugin version 1.5.8 or below is installed. You can use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files in the /wp-content/plugins/ directory for version details.

Impact Analysis

This vulnerability allows unauthenticated attackers to read sensitive data from the WordPress database, including user credentials, personal information, or other confidential data stored in the site's database.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA compliance requirements. It may result in data breaches, legal penalties, and reputational damage due to non-compliance with data protection regulations.

Mitigation Strategies

Immediately update the Site Setup Wizard plugin to the latest version to patch the SQL injection flaw. If an update is unavailable, consider disabling or removing the plugin until a fix is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89195. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart