CVE-2026-14189
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
27/07/2026
Last modified:
27/07/2026
Description
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.
Impact
Base Score 3.x
3.80
Severity 3.x
LOW



