← WordPress Vulnerabilities
WordPress security by component

SAMO Forms

SAMO Forms (samo-forms) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.6.

Plugin slug: samo-forms

CVE-2026-80491: SAMO Forms exposes SQL injection through unauthenticated actions

SAMO Forms through 1.0.0 uses unauthenticated request input in SQL queries without sufficient sanitization, escaping, or query preparation. An attacker can alter those queries and extract sensitive database information. The authoritative export says several actions are affected but does not name the actions, parameters, queries, or tables.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for samo-forms
Safe version
Sep 12, 2026 CVE-2026-80491
SAMO Forms exposes SQL injection through unauthenticated actions
SAMO Forms through 1.0.0 uses unauthenticated request input in SQL queries without sufficient sanitization, escaping, or query preparation. An attacker can alter those queries and extract sensitive database information. The authoritative export says several actions are affected but does not name the actions, parameters, queries, or tables.
See mitigation notes
CVE8.6
NVDPending