CVE-2026-89237
Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name' Parameters
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.
| Vendor | unknown |
| Product | bluff post |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown bluff post
Be the first to know when new unknown vulnerabilities affecting unknown bluff post are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Bluff Post
0 ≤ 1.1.1
References
Credits
João Ramos Maciel WPScan