CVE-2026-87771
Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and read
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
| Vendor | unknown |
| Product | product question and answer |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown product question and answer
Be the first to know when new unknown vulnerabilities affecting unknown product question and answer are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Product Question and Answer
0 ≤ 1.1.0
References
Credits
Theo Antônio Da Fonseca WPScan