PatchSiren

Site Setup Wizard CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Site Setup Wizard CVE published 2026-10-11

CVE-2026-89195

The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database. This vulnerability affects WordPress installations with the Site Setup Wizard plugin, allowing attackers to potentially read sensitive data. Defenders should assess [truncated]