CVE-2026-89237 UNKNOWN

CVE-2026-89237

Published: 2026-09-26

Description

The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…