Unrated severityNVD Advisory· Published Sep 18, 2026
CVE-2026-87771
CVE-2026-87771
Description
The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.1.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.