CVE-2026-80491 PUBLISHED

SAMO Forms <= 1.0.0 - Unauthenticated SQLi

Assigner: WPScan
Reserved: 26.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

Product Status

Vendor Unknown
Product SAMO Forms
Versions Default: unknown
  • affected from 0 to 1.0.0 (incl.)

Credits

  • João Ramos Maciel finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE