---
id: CVE-2026-89303
title: >-
  The Post Voting System WordPress plugin through 1.0 does not properly sanitize
  and escape a parameter before using it in a SQL query, allowing any
  authenticated user to perform SQL injection attacks.
summary: >-
  The Post Voting System WordPress plugin through 1.0 does not properly sanitize
  and escape a parameter before using it in a SQL query, allowing any
  authenticated user to perform SQL injection attacks.
severity: none
cwe:
  - CWE-89
product: Post Voting System
affected:
  - post_voting_system <= 1.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T07:17:21.283'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89303'
references:
  - url: 'https://wpscan.com/vulnerability/dbe62e96-6493-4385-92a2-6281c5428a9f/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T07:04:53.495Z'
---

## Overview

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
