Description
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
Published: 2026-09-28
Score: n/a
EPSS: n/a
KEV: No
Impact: SQL Injection leading to database compromise
Action: Immediate Patch
AI Analysis

Impact

The Post Voting System WordPress plugin up to and including version 1.0 fails to properly sanitize the 'row' parameter before including it in a SQL query, allowing any authenticated user to inject arbitrary SQL code. This flaw can enable an attacker to read, modify, or delete arbitrary database records, potentially exposing sensitive site data or disrupting site functionality. The impact is on data confidentiality and integrity, with possible availability consequences if critical data is altered.

Affected Systems

The vulnerability applies to the Post Voting System WordPress plugin whose versions do not exceed 1.0, with the vendor listed as Unknown:Post Voting System.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, which suggests that widespread exploitation has not been observed yet. However, the presence of a classic SQL injection flaw and the fact that it can be triggered by any authenticated user means that exploitation is technically feasible and would not require special privileges beyond normal plugin usage. In the absence of an available CVSS score, administrators should treat this as a high‑risk flaw because of the ease of exploitation and the potential for serious data compromise.

Generated by OpenCVE AI on September 28, 2026 at 07:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Post Voting System plugin to a version that addresses the SQL injection vulnerability or replace the plugin with a secure alternative.
  • If an update is unavailable, remove the plugin entirely from the WordPress installation to eliminate the attack surface.
  • Configure a web application firewall or input validation rule set to detect and block malicious SQL payloads targeting the 'row' parameter, ensuring that future adaptations of the plugin do not reintroduce the flaw.

Generated by OpenCVE AI on September 28, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Mon, 28 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
Title Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-28T06:00:18.974Z

Reserved: 2026-09-11T13:40:25.498Z

Link: CVE-2026-89303

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T07:17:21.283

Modified: 2026-09-28T07:17:21.283

Link: CVE-2026-89303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T07:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')