๐Ÿ” CVE Alert

CVE-2026-89213

UNKNOWN 0.0

Llavero.io <= 0.1.4 - Unauthenticated Blind SQLi via 'cill_login' Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

Vendor unknown
Product llavero.io
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown llavero.io

Be the first to know when new unknown vulnerabilities affecting unknown llavero.io are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Llavero.io
0 โ‰ค 0.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3f190943-997c-4b94-b760-51532b61427f/

Credits

RIA Labs WPScan