PatchSiren

ASPL CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review ASPL CVE published 2026-10-11

CVE-2026-89287

The ASPL Product Quotation WordPress plugin through 1.1.0 is vulnerable to SQL injection due to a lack of sanitization and escaping of a parameter used in SQL statements. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database. The vulnerability requires verification of the plugin version and presence in WordPress installations, and potential updates to pre [truncated]