HIGH

CVE-2026-80491

2026-09-12 CVSS v3.1
CVSS
8.6

Description

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

0.32%
Probability of exploitation in next 30 days
25.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE