CVE-2026-89287: ASPL Product Quotation <= 1.1.0 - Unauthenticated SQLi via 'quote_id' Parameter
Published Oct 11, 2026
·Updated
The ASPL Product Quotation WordPress plugin through 1.1.0 does not sanitize and escape a parameter before using it in SQL statements, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.
Affected Software
1 affected component
Aspl Product Quotation<=1.1.0
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated attackers can exploit it; no WordPress account or plugin-level privileges are required.
2
What access does exploitation provide?
Successful SQL injection can allow an attacker to read arbitrary data from the WordPress database.
3
Which plugin versions are affected?
ASPL Product Quotation versions through 1.1.0 are affected.
4
Which input is vulnerable?
The vulnerable input is the quote_id parameter, which is used in SQL statements without adequate sanitization and escaping.