Review
SPS‑Suite
CVE published 2026-09-28
CVE-2026-93000
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks. This vulnerability can lead to potential SQL injection attacks against unauthenticated users and possible data extraction or modification through SQL injection. Defenders responsib [truncated]