CVE-2026-14189: Unknown Wpbot
Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.
Affected products
- Unknown Wpbot: before 8.5.2 (fixed in 8.5.2)
Published 2026-07-27. Last modified 2026-07-27.