Description
The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.
Published: 2026-10-11
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

The Social Web Suite WordPress plugin up to version 4.1.12 fails to require the shared secret before processing authorization requests and does not sanitize a query parameter used in an SQL statement. Unauthenticated users can therefore send crafted requests that result in blind SQL injection, enabling them to read or modify database contents and potentially compromise the confidentiality and integrity of the site.

Affected Systems

WordPress sites running the Social Web Suite plugin version 4.1.12 or earlier are affected. The vulnerability exists in the plugin's handling of authentication requests, regardless of the shared secret setting.

Risk and Exploitability

Because the flaw is exploitable without authentication and no secret is required, any remote user can invoke the vulnerable endpoint. No public exploits are currently documented and the EPSS score is not available; however, the absence of a KEV listing does not remove the risk. The attack vector is inferred to be remote over HTTP(S) due to the nature of a WordPress plugin. The potential impact includes unauthorized data exfiltration and data modification, with a high likelihood of exploitation if the attacker can enumerate the vulnerable endpoint.

Generated by OpenCVE AI on October 11, 2026 at 07:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Social Web Suite WordPress plugin to a version newer than 4.1.12 where the shared‑secret validation and SQL sanitization have been implemented.
  • If an upgrade is not immediately possible, configure the plugin to enforce the presence and correctness of the shared secret before any authorization logic is executed, ensuring that the vulnerable code path is never reached.
  • Deploy a web application firewall rule or similar filtering that blocks suspect SQL patterns on the endpoint handling the plugin’s requests.
  • (Optional) Disable or remove the Social Web Suite plugin if it is not needed for site functionality.

Generated by OpenCVE AI on October 11, 2026 at 07:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.
Title Social Web Suite <= 4.1.12 - Unauthenticated Blind SQLi via Unset Shared Secret
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:42.483Z

Reserved: 2026-09-10T14:12:13.403Z

Link: CVE-2026-88930

cve-icon Vulnrichment

Updated: 2026-10-11T11:17:48.956Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:27.603

Modified: 2026-10-11T12:17:26.293

Link: CVE-2026-88930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:45:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')