CVE-2026-14238
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
10/08/2026
Last modified:
11/08/2026
Description
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.
Impact
Base Score 3.x
4.10
Severity 3.x
MEDIUM


