PatchSiren

Loja Automática CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Loja Automática CVE published 2026-10-11

CVE-2026-89297

CVE-2026-89297 is a SQL injection vulnerability in the Loja Automática WordPress plugin through version 1.0.0. The vulnerability allows unauthenticated users to perform SQL injection attacks. Defenders responsible for WordPress installations with the Loja Automática plugin should assess exposure and prioritize verification and potential patching. The CVE record was published on 2026-10-11T07:17:28.670Z an [truncated]