ExploitMatch
Back

CVE-2026-89195

Monitor on ThreatCluster

Description

The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.