CVE-2026-14238EPSS p5.9%
CVE-2026-14238CVE-2026-14238
Description
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.
Scoring
| CVSS | 4.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
| EPSS | 0.16% probability of exploitation · percentile 5.9% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-11 |