Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-88930
CVE-2026-88930
Description
The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=4.1.12
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.