CVE-2026-93000 The SPS-Suite WordPress plugin through 1.4.0 does not… — CVE Notify — TG.ME

🚨 CVE-2026-93000
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.

🎖@cveNotify
WPScan
SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search
See details on SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search CVE 2026-93000. View the latest Plugin Vulnerabilities on WPScan.
September 28, 2026 62