CVE-2026-89214: WpCues Basic Quiz <= 1.6.5 - Unauthenticated SQLi via Quiz Result Submission
Published Oct 11, 2026
·Updated
The WpCues Basic Quiz WordPress plugin through 1.6.5 does not properly sanitise and escape values before using them in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.
Affected Software
1 affected component
WpCues Basic Quiz WordPress plugin<=1.6.5
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker does not need to authenticate. Any deployment running an affected version through 1.6.5 is exposed to unauthenticated SQL injection through quiz result submission.
2
What could an attacker obtain through exploitation?
The flaw allows SQL injection attacks that can read data from the WordPress database.