CVE-2026-89303: Unknown Post Voting System
Medium severity, CVSS 6.4. EPSS: 0.1% chance of exploitation in the next 30 days.
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
Affected products
- Unknown Post Voting System: up to and including 1.0
Published 2026-09-28. Last modified 2026-09-28.