ExploitMatch
Back

CVE-2026-89287

Monitor on ThreatCluster

Description

The ASPL Product Quotation WordPress plugin through 1.1.0 does not sanitize and escape a parameter before using it in SQL statements, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.