CVE-2026-87771: Unknown Product Question And Answer

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

Affected products

  • Unknown Product Question And Answer: up to and including 1.1.0

Published 2026-09-18. Last modified 2026-09-18.