🔐 CVE Alert

CVE-2026-89237

UNKNOWN 0.0

Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name' Parameters

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.

Vendor unknown
Product bluff post
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown bluff post

Be the first to know when new unknown vulnerabilities affecting unknown bluff post are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Bluff Post
0 ≤ 1.1.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/92355b31-995b-4151-a414-51d3430d0fd6/

Credits

João Ramos Maciel WPScan