SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-80491

HIGH · CVSS 8.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The SAMO Forms WordPress plugin, up to version 1.0.0, is vulnerable to SQL injection due to inadequate sanitization and escaping of user input in multiple unauthenticated actions. This flaw allows unauthenticated attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize immediate updates or mitigation measures to safeguard against potential exploitation.

CVE
CVE-2026-80491
Severity
HIGH
CVSS
8.6
EPSS
0.32%
WordPress

Original NVD Description

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.