CVE-2026-89303: Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter
Published Sep 28, 2026
·Updated
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
Affected Software
1 affected component
WordPress Post Voting System<=1.0
Event History
Sep 28, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users can exploit this issue?
Any authenticated WordPress user can exploit it, including users with Subscriber-level access or higher. The issue is therefore relevant where untrusted users can register for or otherwise obtain accounts.
2
What input is involved in the injection?
The vulnerable input is the row parameter, which is used in a SQL query without proper sanitization and escaping.
3
Are deployments on the current plugin release affected?
The issue affects Post Voting System versions through 1.0. The provided information does not identify a fixed version.