CVE-2026-89296: Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter
Published Oct 1, 2026
·Updated
The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Affected Software
1 affected component
Pro Like Button<2.0
Event History
Oct 1, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
WordPress sites using Pro Like Button versions earlier than 2.0 are affected. The provided information does not identify any configuration requirement or exception.
2
What access does an attacker need?
An attacker can exploit the issue remotely over the network without authentication, privileges, or user interaction. The affected input is the postid parameter.