Description
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
Published: 2026-09-12
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized database access and potential data alteration
Action: Immediate Patch
AI Analysis

Impact

The SAMO Forms WordPress plugin through version 1.0.0 fails to properly sanitize and escape user input before incorporating it into SQL queries in several actions that do not require authentication. The flaw is a CWE-89 SQL injection, permitting attackers to inject arbitrary SQL statements, enabling them to read sensitive data, alter stored information, or delete database records. The vulnerability does not grant code execution, but the impact on confidentiality, integrity, and availability of the database is significant.

Affected Systems

All WordPress sites that have the SAMO Forms plugin installed at version 1.0.0 or earlier are affected.

Risk and Exploitability

The flaw can be exploited remotely with no authentication, and the associated CVSS score of 8.6 indicates a high damage potential. Although the EPSS score is less than 1%, the absence of authentication requirements and the high impact classifies the risk as high. The vulnerability is not present in the CISA KEV catalog; however,.

Generated by OpenCVE AI on September 15, 2026 at 19:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SAMO Forms to the latest version.
  • If an upgrade cannot be performed immediately, use a web application firewall or server‑side rules to block or log suspicious SQL‑like input patterns on the plugin’s unauthenticated endpoints.
  • As a temporary measure, disable or require authentication for all features that submit data until a secure version is available.

Generated by OpenCVE AI on September 15, 2026 at 19:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
Title SAMO Forms <= 1.0.0 - Unauthenticated SQLi
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:34:36.567Z

Reserved: 2026-08-26T13:33:05.289Z

Link: CVE-2026-80491

cve-icon Vulnrichment

Updated: 2026-09-12T15:23:51.695Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:25.403

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-80491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')