CVE-2026-93000: Unknown Sps-Suite

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.

Affected products

  • Unknown Sps-Suite: up to and including 1.4.0

Published 2026-09-28. Last modified 2026-09-28.