CVE-2026-80491

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

  • Published Sep 12, 2026
  • CVSS 8.6 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-80491 at the National Vulnerability Database