🔐 CVE Alert

CVE-2026-89195

UNKNOWN 0.0

Site Setup Wizard <= 1.5.8 - Unauthenticated SQLi via ssw_check_admin_email_exists

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

Vendor unknown
Product site setup wizard
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown site setup wizard

Be the first to know when new unknown vulnerabilities affecting unknown site setup wizard are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Site Setup Wizard
0 ≤ 1.5.8

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/fdc222cf-8056-47c5-99a3-f0c928dfc1f8/

Credits

João Ramos Maciel WPScan