🔐 CVE Alert

CVE-2026-89297

UNKNOWN 0.0

Loja Automática <= 1.0.0 - Unauthenticated SQLi via 'id' Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Loja Automática WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Vendor unknown
Product loja automática
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown loja automática

Be the first to know when new unknown vulnerabilities affecting unknown loja automática are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Loja Automática
0 ≤ 1.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/590abff1-6ffd-48ce-a722-12655ab78a7a/

Credits

Naoki Kawahigashi WPScan