Vulnerability record · CVE-2026-93000 · published 28 September 2026
CVE-2026-93000: The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query…
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
Description
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
References
Track CVE-2026-93000 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2026-93000), CISA KEV, FIRST EPSS. This page is refreshed as NVD updates the record.