Sceawere

Vulnerability Detail

CVE-2026-89302UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Post Voting System SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
8h ago
Vendor
Unknown
Product
Post Voting System
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-11T07:17:28.873Z",
  "pubdate": "2026-10-11T07:17:28.873Z",
  "executiveSummary": "The Post Voting System WordPress plugin, in versions through 1.0, is susceptible to an unauthenticated SQL injection vulnerability. This security flaw originates from the improper sanitization and escaping of user-supplied input before it is incorporated into database queries. By manipulating parameters processed by the plugin, a remote, unauthenticated attacker can execute arbitrary SQL commands within the application's backend database.\nThe risk implication of this vulnerability is critical, as it potentially grants an attacker unauthorized access to sensitive data, including administrative credentials, user records, and configuration settings. Furthermore, an attacker may be able to modify, delete, or exfiltrate data, leading to a complete compromise of the site's integrity and confidentiality. Because the vulnerability does not require authentication, it is highly accessible to malicious actors seeking to exploit WordPress environments. Remediation requires an immediate update to a patched version or, if unavailable, the implementation of strict input filtering and the use of prepared statements to prevent malicious SQL code execution.",
  "technicalDetails": "The vulnerability exists due to the failure of the Post Voting System WordPress plugin to implement secure data handling practices during database interactions. Specifically, the plugin takes input from a user-supplied parameter and passes it directly into a SQL query without first applying essential security measures such as sanitization, validation, or escaping. This allows an attacker to break out of the intended query structure and inject arbitrary SQL syntax.\nThe attack flow begins when a remote, unauthenticated user sends a specifically crafted HTTP request to the vulnerable endpoint associated with the Post Voting System plugin. Within this request, the attacker includes a malicious payload in the vulnerable parameter. Because the application logic fails to distinguish between data and executable code, the database engine interprets the malicious input as part of the query command. This allows the attacker to alter the query logic, enabling them to bypass existing checks, perform UNION-based attacks to extract data from other tables, or potentially execute stacked queries if the database configuration permits.\nThe vulnerable component is the plugin's internal database interaction logic, which lacks the implementation of parameterized queries or prepared statements—the industry-standard defense against SQL injection. By neglecting these practices, the plugin essentially trusts user input, providing an injection vector for any actor with network access to the target WordPress installation.\nExploitation does not require prior knowledge of the WordPress environment, administrative privileges, or authenticated session tokens. Once the payload is successfully executed, the post-exploitation impact is severe. An attacker can perform reconnaissance to enumerate database tables, escalate privileges by modifying user roles, or extract sensitive configurations. In scenarios where database permissions are overly broad, an attacker might even be able to perform file system operations or execute system-level commands through database-specific functions. This vulnerability remains present in all versions through 1.0, making it a critical threat to the security of affected WordPress sites until addressed by a formal security update."
}
CVE-2026-89302: Post Voting System SQL Injection (HIGH Severity, CVSS: 8.6) | Sceawere