# CVE-2026-80491

## Summary

- **CVE ID:** CVE-2026-80491
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** N/A
- **Published:** Sep 12, 2026
- **Last Modified:** Sep 12, 2026

## Description

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

## Affected Products

- Unknown — SAMO Forms (0)

## References

- [CNA](https://wpscan.com/vulnerability/765e7131-2eb4-41df-a1e0-05c8a89cb88c/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 25.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._