What is CVE-2026-14189?
CVE-2026-14189: The WPBot WordPress plugin before version 8.5.2 fails to validate administrator-configured field identifiers before using them in a SQL query. This allows users with administrator access to perform SQL injection attacks that execute when a visitor triggers a search. Websites using this plugin should immediately update to version 8.5.2 or higher.
Azərbaycanca: CVE-2026-14189: WPBot WordPress plaginin 8.5.2-dən əvvəlki versiyalarında administrator tərəfindən konfiqurasiya edilən sahə identifikatorları SQL sorğusunda istifadə edilməzdən əvvəl yoxlanılmır. Bu zəiflik administrator girişi olan istifadəçilərə, ziyarətçi axtarış etdikdə icra olunan SQL injection həyata keçirməyə imkan verir. Plagindən istifadə edən veb-saytlar dərhal 8.5.2 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WPBot plugin are affected by CVE-2026-14189?
CVE-2026-14189 affects the WPBot WordPress plugin before version 8.5.2.
What privileges does an attacker need to exploit this vulnerability?
The attacker must be a user with administrator access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.