SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14189

LOW · CVSS 3.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The WPBot WordPress plugin prior to version 8.5.2 is vulnerable to SQL injection due to insufficient validation of administrator-configured field identifiers in SQL queries. This flaw allows users with administrator access to execute arbitrary SQL commands when a visitor initiates a search, potentially compromising the database. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14189
Severity
LOW
CVSS
3.8
EPSS
0.16%
WordPress

Original NVD Description

The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.