---
id: CVE-2026-80491
title: >-
  The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and
  escape user input before using it in SQL queries in several unauthenticated
  actions, allowing unauthenticated attackers to perform SQL injection attacks.
summary: >-
  The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and
  escape user input before using it in SQL queries in several unauthenticated
  actions, allowing unauthenticated attackers to perform SQL injection attacks.
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-89
product: SAMO Forms
affected:
  - samo_forms <= 1.0.0
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80491'
references:
  - url: 'https://wpscan.com/vulnerability/765e7131-2eb4-41df-a1e0-05c8a89cb88c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00324
epssPercentile: 0.25721
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-12T15:25:20.162618Z'
ingestedAt: '2026-09-14T15:23:07.478Z'
---

## Overview

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
