CVE-2026-80491
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
- Published Sep 12, 2026
- CVSS 8.6 high
- 0.4% chance of exploitation in the next 30 days (EPSS)