CVE-2026-89299: WP Verify API <= 1.0.0 - Unauthenticated SQLi via 'verify' Parameter
Published Oct 11, 2026
·Updated
The WP Verify API WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Affected Software
1 affected component
WP Verify API<=1.0.0
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated users can exploit the SQL injection flaw; no login or WordPress account is required.
2
Which plugin versions are affected?
WP Verify API versions through 1.0.0 are affected.
3
What input is involved in the vulnerable query?
The vulnerability is associated with the plugin's verify parameter, which is not properly sanitized and escaped before being used in a SQL query.