Description
The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.
Published: 2026-10-11
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated SQL injection that allows read-attack on the database
Action: Immediate Patch
AI Analysis

Impact

A parameter handled by the Site Setup Wizard WordPress plugin is used directly in a SQL statement without proper sanitisation or escaping, enabling attackers who need no authentication to inject statements and read data from the database. The impact is the disclosure of all database contents the plugin’s database user can access, potentially including user credentials, site content, and configuration information.

Affected Systems

The vulnerability affects the Site Setup Wizard WordPress plugin version 1.5.8 and earlier. The plugin is listed under an unknown vendor, but any WordPress installation using this plugin build should be considered exposed.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA KEV. Because authentication is not required and the flaw permits data extraction, the theoretical risk is high, but the lack of an EPSS rating means the current exploitation probability is uncertain. Without a CVSS score definition, the severity cannot be quantified precisely, yet any attacker with network access to the site could exploit the flaw as soon as the plugin is installed or kept at the vulnerable version.

Generated by OpenCVE AI on October 11, 2026 at 07:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Site Setup Wizard to a version newer than 1.5.8, which contains the input sanitisation fix.
  • If an upgrade cannot be applied immediately, disable or protect the ssw_check_admin_email_exists endpoint from unauthenticated access using web‑application‑firewall rules or by adding a simple authentication check.
  • Review the database user permissions granted to WordPress and restrict them to the minimum necessary for normal operation, limiting the damage an exploit could achieve.

Generated by OpenCVE AI on October 11, 2026 at 07:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.
Title Site Setup Wizard <= 1.5.8 - Unauthenticated SQLi via ssw_check_admin_email_exists
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:42.359Z

Reserved: 2026-09-11T07:45:16.217Z

Link: CVE-2026-89195

cve-icon Vulnrichment

Updated: 2026-10-11T11:17:34.819Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:27.720

Modified: 2026-10-11T12:17:26.440

Link: CVE-2026-89195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:45:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')