Sceawere
Vulnerability Detail
CVE-2026-89214UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WpCues SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- WpCues Basic Quiz
- Attack Type
- CWE-89 SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WpCues Basic Quiz WordPress plugin through 1.6.5 does not properly sanitise and escape values before using them in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-11T07:17:27.957Z",
"pubdate": "2026-10-11T07:17:27.957Z",
"executiveSummary": "The WpCues Basic Quiz WordPress plugin, specifically in versions up to 1.6.5, contains a critical SQL injection vulnerability.\nThis flaw stems from inadequate sanitization and escaping of user-supplied input before it is incorporated into database queries.\nThe vulnerability allows unauthenticated, remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized data exfiltration from the underlying database.\nThe impact is significant, as successful exploitation bypasses standard application authentication, granting the attacker access to sensitive information stored within the WordPress database tables.\nThis represents a high-risk security flaw that compromises the confidentiality and integrity of the affected WordPress installation.\nNo specific privileges or authentication are required to trigger the exploit, increasing the threat level for all sites running the vulnerable plugin version.",
"technicalDetails": "The vulnerability exists due to a failure in the plugin's data handling logic, where user-controllable input is directly concatenated into SQL statements without the use of proper parameterization or sanitization functions.\nThis root cause allows an attacker to manipulate the structure of the backend database queries by injecting malicious SQL fragments.\nThe attack flow commences when an unauthenticated actor submits a crafted request containing malicious input parameters to the vulnerable endpoint within the WpCues Basic Quiz plugin.\nSince the input is not processed through WordPress security APIs like $wpdb->prepare() or other escaping mechanisms (e.g., esc_sql(), sanitize_text_field()), the database driver executes the injected malicious SQL code as part of the intended query.\nAn attacker can leverage this primitive to perform UNION-based SQL injection, which allows the retrieval of data from other tables within the database schema, including sensitive information such as user credentials, configuration details, or other plugin data.\nFurthermore, the vulnerability can be exploited to conduct error-based or blind SQL injection, enabling the attacker to infer database contents bit by bit if direct output is not reflected.\nThe impact of this exploit is severe, as it grants full access to the database layer without requiring prior authentication or administrative privileges. The attacker is essentially operating with the permissions of the database user configured for the WordPress site, which often possesses broad read/write access.\nIn terms of network exposure, the vulnerability is reachable over the internet, requiring only basic knowledge of the plugin's URL structure and query parameters.\nThe plugin is confirmed vulnerable in versions up to 1.6.5. Because the vulnerability is rooted in the absence of input validation at the plugin's entry points, it remains exploitable until the code is patched to utilize proper database abstraction and sanitization methods."
}