CVE-2026-89297: Loja Automática <= 1.0.0 - Unauthenticated SQLi via 'id' Parameter
Published Oct 11, 2026
·Updated
The Loja Automática WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Affected Software
1 affected component
Loja Automática Loja Automática WordPress plugin<=1.0.0
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated users can exploit the vulnerable parameter, so no WordPress account or prior authentication is required.
2
Which plugin versions are affected?
The issue affects Loja Automática WordPress plugin versions through 1.0.0.
3
What is the vulnerable input?
The vulnerable input is the id parameter, which is used in a SQL query without proper sanitization and escaping.