CVE-2026-93000

The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.

Credits

Pablo González Pérez
Francisco José Ramírez Vicente
and Iñigo Sánchez Enciso
WPScan

References