CVE-2026-14189: Unknown Wpbot

Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.

Affected products

  • Unknown Wpbot: before 8.5.2 (fixed in 8.5.2)

Published 2026-07-27. Last modified 2026-07-27.