CVE-2026-89235: Testimonials by BestWebSoft 1.0.5 - 1.0.8 - Unauthenticated SQLi via 'offset' Parameter
Published Oct 9, 2026
·Updated
The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.
Affected Software
1 affected component
Bestwebsoft Testimonials>=1.0.5<=1.0.8
Event History
Oct 9, 2026
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
BestWebSoft Testimonials versions 1.0.5 through 1.0.8 are identified as affected. The issue is in the WordPress plugin.
2
Does exploitation require an account or user interaction?
No. The vulnerability is described as unauthenticated, with no privileges or user interaction required.
3
What must an attacker do to exploit this issue?
An attacker must send a request containing malicious SQL through the offset parameter. Exploitation has high attack complexity according to the supplied vector.