A vulnerability, which was classified as critical, was found in wupsales AI Chatbot & Workflow Automation by AIWU Plugin up to 1.4.17 on WordPress. This issue affects the function getListForTbl. Executing a manipulation can lead to sql injection.

This vulnerability appears as CVE-2026-2993. The attack may be performed from remote. There is no available exploit.

A patch should be applied to remediate this issue.