CVE-2026-87963: Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter
Published Sep 17, 2026
·Updated
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
Affected Software
1 affected component
Yo WordPress plugin>=1.1<=1.3.1
Event History
Sep 17, 2026
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit it. No credentials or user interaction are required.
2
What information could an attacker obtain?
The issue allows SQL injection that can be used to read arbitrary contents of the WordPress database, including administrator password hashes.
3
Which plugin versions are affected?
Yo WordPress plugin versions 1.1 through 1.3.1 are affected.