Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-89237 1 Wordpress-extensions 1 Bluff Post 2026-09-26 6.8 Medium
The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.