PatchSiren

Recordbrowser CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Recordbrowser CVE published 2026-10-11

CVE-2026-89232

The Recordbrowser WordPress plugin through 1.1.7 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. This SQL injection vulnerability enables attackers to potentially extract sensitive information from the database or inject malicious SQL queries, increasing the ris [truncated]