Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sun, 11 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-89 |
Sun, 11 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Verify API WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Title | WP Verify API <= 1.0.0 - Unauthenticated SQLi via 'verify' Parameter | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-11T11:32:40.885Z
Reserved: 2026-09-11T13:18:06.942Z
Link: CVE-2026-89299
Updated: 2026-10-11T11:14:53.005Z
Status : Received
Published: 2026-10-11T07:17:28.770
Modified: 2026-10-11T12:17:27.783
Link: CVE-2026-89299
No data.
OpenCVE Enrichment
Updated: 2026-10-11T08:00:13Z
