🔐 CVE Alert

CVE-2026-89214

UNKNOWN 0.0

WpCues Basic Quiz <= 1.6.5 - Unauthenticated SQLi via Quiz Result Submission

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WpCues Basic Quiz WordPress plugin through 1.6.5 does not properly sanitise and escape values before using them in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

Vendor unknown
Product wpcues basic quiz
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpcues basic quiz

Be the first to know when new unknown vulnerabilities affecting unknown wpcues basic quiz are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / WpCues Basic Quiz
0 ≤ 1.6.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/c5c57e38-61e9-456b-a56e-ef25146ee28f/

Credits

João Ramos Maciel WPScan