🚨 CVE-2026-89303
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
🎖@cveNotify
WPScan
Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter
See details on Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter CVE 2026-89303. View the latest Plugin Vulnerabilities on WPScan.

September 28, 2026 39