CVE-2026-80491: Unknown Samo Forms
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
Affected products
- Unknown Samo Forms: up to and including 1.0.0
Published 2026-09-12. Last modified 2026-09-14.