PT-2026-90564 · Undefined · Undefined

CVE-2026-80491

·

Published

2026-09-12

·

Updated

2026-09-24

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAMO Forms WordPress plugin version 1.0.0
Description Insufficient sanitization and escaping of user input in several unauthenticated actions allows unauthenticated attackers to execute SQL injection attacks. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80491

Affected Products

Undefined