Review
Llavero.io
CVE published 2026-10-11
CVE-2026-89213
The Llavero.io WordPress plugin through 0.1.4 is vulnerable to SQL injection attacks. This vulnerability allows unauthenticated attackers to read data from the database by exploiting a parameter that is not properly sanitized and escaped before being used in a SQL statement. The vulnerability has been publicly disclosed and defenders responsible for WordPress installations that use the Llavero.io plugin s [truncated]