CVE-2026-89237
MEDIUM
NVD
CVSS Score
6.8
Severity
MEDIUM
Published
Sep 26, 2026
Vendor
unknown
Description
The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.