CVE-2026-87771 PUBLISHED

Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and read

Assigner: WPScan
Reserved: 09.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

Product Status

Vendor Unknown
Product Product Question and Answer
Versions Default: unknown
  • affected from 0 to 1.1.0 (incl.)

Credits

  • Theo Antônio Da Fonseca finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE