CVE-2026-89302
Received Received - Intake

SQL Injection in Post Voting System WordPress Plugin

Vulnerability report for CVE-2026-89302, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Post Voting System 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Post Voting System WordPress plugin through version 1.0 has a flaw where it does not properly sanitize and escape the 'id' parameter before using it in SQL queries. This allows unauthenticated users to inject malicious SQL commands, potentially accessing or modifying database contents.

Detection Guidance

To detect this vulnerability, check if the Post Voting System WordPress plugin version 1.0 or below is installed. Look for unauthenticated SQL injection attempts targeting the 'id' parameter in SQL queries. Monitor logs for suspicious database queries or errors indicating SQL injection.

Impact Analysis

This vulnerability could allow attackers to steal sensitive data, manipulate database records, or take control of your WordPress site without needing to log in. It may lead to unauthorized access to user information, posts, or other critical data stored in the database.

Compliance Impact

This SQL injection flaw could result in unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection. Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance with these regulations.

Mitigation Strategies

Immediately uninstall or disable the Post Voting System WordPress plugin if installed. Apply any available patches or updates if released. Implement web application firewalls to block SQL injection attempts. Monitor network traffic for unusual database queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89302. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart