Sceawere

Vulnerability Detail

CVE-2026-89195UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Site Setup Wizard SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
8h ago
Vendor
Unknown
Product
Site Setup Wizard
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-11T07:17:27.720Z",
  "pubdate": "2026-10-11T07:17:27.720Z",
  "executiveSummary": "The Site Setup Wizard WordPress plugin, in versions up to and including 1.5.8, is vulnerable to a critical SQL injection (SQLi) vulnerability.\nThis flaw arises from the improper sanitization and escaping of user-supplied input before it is incorporated into database queries.\nSuccessful exploitation allows an unauthenticated, remote attacker to execute arbitrary SQL commands against the underlying database.\nThe impact of this vulnerability is severe, potentially leading to unauthorized data exfiltration, modification of database content, or the disclosure of sensitive information such as administrative credentials and user data.\nBecause the vulnerability is accessible without authentication, it poses a significant risk to the integrity and confidentiality of the WordPress installation.\nAttackers can leverage this flaw by sending specifically crafted HTTP requests to the target application to manipulate backend database interactions.",
  "technicalDetails": "The vulnerability exists due to a failure in the plugin's input handling logic, where a parameter is processed by an SQL statement without utilizing proper parameterization or adequate sanitization mechanisms such as the WordPress $wpdb->prepare() function.\nThis creates an injection vector where user-supplied input can alter the structure of the intended SQL query, allowing the attacker to inject malicious SQL syntax.\nThe attack flow begins when an unauthenticated attacker sends a crafted HTTP GET or POST request to the plugin's endpoint containing a malicious payload in the vulnerable parameter.\nSince the input is not validated, the application concatenates the malicious input directly into the database query, causing the database to execute the attacker's injected code alongside the legitimate query.\nBy manipulating the SQL query, an attacker can utilize UNION-based techniques to append results from other tables in the database, or employ time-based blind SQL injection to infer data content through response latency.\nThe scope of the impact is broad, as the database user associated with the WordPress installation often has sufficient privileges to read, update, or drop tables, which may lead to full site takeover if configuration data or administrator session tokens are retrieved.\nThe root cause is a lack of rigorous input validation and the omission of secure coding practices during database interactions within the plugin source code.\nThe vulnerability affects all versions of the Site Setup Wizard plugin up to 1.5.8 and requires no prior access or credentials to initiate the exploit sequence.\nAs this interaction occurs at the web server layer, it is exposed to any network entity capable of reaching the WordPress instance.\nPost-exploitation, an attacker can potentially extract the site's entire database, including users, passwords (if hashed), and configuration settings, which can be further utilized to pivot into the administrative backend or escalate privileges within the WordPress environment."
}
CVE-2026-89195: Site Setup Wizard SQL Injection (HIGH Severity, CVSS: 8.6) | Sceawere