Review
Site Setup Wizard
CVE published 2026-10-11
CVE-2026-89195
The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database. This vulnerability affects WordPress installations with the Site Setup Wizard plugin, allowing attackers to potentially read sensitive data. Defenders should assess [truncated]