CVE-2026-93000: Unknown Sps-Suite
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
Affected products
- Unknown Sps-Suite: up to and including 1.4.0
Published 2026-09-28. Last modified 2026-09-28.