CVE-2026-89304: Paymendo Bank Transfer <= 1.1 - Unauthenticated Blind SQLi via 'paymendo_bank_transfer_completed_payment' Parameter
The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform blind SQL injection attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue can be exploited by unauthenticated users; no WordPress account or administrative access is required.
Which installations are affected?
Paymendo Bank Transfer versions through 1.1 are affected. The provided information does not identify any configuration prerequisite, so affected versions should be treated as exposed where the vulnerable functionality is reachable.
What can an attacker do with this vulnerability?
An attacker can conduct blind SQL injection through the paymendo_bank_transfer_completed_payment parameter. Because the injection is blind, the available data does not establish what database information can be extracted or whether data can be modified.