SQL Injection Vulnerability in SAMO Forms Plugin for WordPress
CVE-2026-80491

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
12 September 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-80491?

The SAMO Forms plugin for WordPress, prior to version 1.0.0, contains a vulnerability that fails to properly sanitize and escape user input in SQL queries during various unauthenticated actions. This flaw enables attackers to potentially execute SQL injection attacks, compromising the integrity and security of the database. Website owners using this plugin should implement the latest updates and ensure secure coding practices to mitigate the risk of such attacks.

Affected Version(s)

SAMO Forms 0 <= 1.0.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Ramos Maciel
WPScan
.