CVE-2026-88930: Social Web Suite <= 4.1.12 - Unauthenticated Blind SQLi via Unset Shared Secret
The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to unauthenticated exploitation?
Sites running the Social Web Suite WordPress plugin version 4.1.12 or earlier are affected if the plugin's shared secret has not been set. An attacker does not need to authenticate because requests can be accepted as authorised when that secret is unset.
What capability does successful exploitation provide?
An unauthenticated attacker can perform blind SQL injection through a parameter that is used in an SQL statement without sanitisation and escaping. The available information does not state which database data can be accessed or modified.
How can I determine whether my site is affected?
Check whether the Social Web Suite WordPress plugin is installed at version 4.1.12 or earlier, and review its configuration to determine whether its shared secret is unset. Both conditions are relevant to the described unauthenticated attack path.