CVE-2026-80491EPSS p36.5%
CVE-2026-80491CVE-2026-80491
Description
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
Scoring
| CVSS | 8.6 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 0.45% probability of exploitation · percentile 36.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-14 |