Sceawere

Vulnerability Detail

CVE-2026-89214UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WpCues SQL Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
8h ago
Vendor
Unknown
Product
WpCues Basic Quiz
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WpCues Basic Quiz WordPress plugin through 1.6.5 does not properly sanitise and escape values before using them in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-11T07:17:27.957Z",
  "pubdate": "2026-10-11T07:17:27.957Z",
  "executiveSummary": "The WpCues Basic Quiz WordPress plugin, specifically in versions up to 1.6.5, contains a critical SQL injection vulnerability.\nThis flaw stems from inadequate sanitization and escaping of user-supplied input before it is incorporated into database queries.\nThe vulnerability allows unauthenticated, remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized data exfiltration from the underlying database.\nThe impact is significant, as successful exploitation bypasses standard application authentication, granting the attacker access to sensitive information stored within the WordPress database tables.\nThis represents a high-risk security flaw that compromises the confidentiality and integrity of the affected WordPress installation.\nNo specific privileges or authentication are required to trigger the exploit, increasing the threat level for all sites running the vulnerable plugin version.",
  "technicalDetails": "The vulnerability exists due to a failure in the plugin's data handling logic, where user-controllable input is directly concatenated into SQL statements without the use of proper parameterization or sanitization functions.\nThis root cause allows an attacker to manipulate the structure of the backend database queries by injecting malicious SQL fragments.\nThe attack flow commences when an unauthenticated actor submits a crafted request containing malicious input parameters to the vulnerable endpoint within the WpCues Basic Quiz plugin.\nSince the input is not processed through WordPress security APIs like $wpdb->prepare() or other escaping mechanisms (e.g., esc_sql(), sanitize_text_field()), the database driver executes the injected malicious SQL code as part of the intended query.\nAn attacker can leverage this primitive to perform UNION-based SQL injection, which allows the retrieval of data from other tables within the database schema, including sensitive information such as user credentials, configuration details, or other plugin data.\nFurthermore, the vulnerability can be exploited to conduct error-based or blind SQL injection, enabling the attacker to infer database contents bit by bit if direct output is not reflected.\nThe impact of this exploit is severe, as it grants full access to the database layer without requiring prior authentication or administrative privileges. The attacker is essentially operating with the permissions of the database user configured for the WordPress site, which often possesses broad read/write access.\nIn terms of network exposure, the vulnerability is reachable over the internet, requiring only basic knowledge of the plugin's URL structure and query parameters.\nThe plugin is confirmed vulnerable in versions up to 1.6.5. Because the vulnerability is rooted in the absence of input validation at the plugin's entry points, it remains exploitable until the code is patched to utilize proper database abstraction and sanitization methods."
}
CVE-2026-89214: WpCues SQL Injection Vulnerability (HIGH Severity, CVSS: 8.6) | Sceawere