CVE-2026-88930 PUBLISHED

Social Web Suite <= 4.1.12 - Unauthenticated Blind SQLi via Unset Shared Secret

Assigner: WPScan
Reserved: 10.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.

Product Status

Vendor Unknown
Product Social Web Suite
Versions Default: unknown
  • affected from 0 to 4.1.12 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE