CVE-2026-89237
EUVD-2026-8752726.09.2026, 07:17
The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.