CVE-2026-89234: WP-Partner <= 1.2.1 - Unauthenticated SQLi via 'id' Parameter
Published Oct 11, 2026
·Updated
The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
Affected Software
1 affected component
WP-Partner<=1.2.1
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description