CVE-2026-89305: Paymendo Bank Transfer <= 1.1 - Subscriber+ SQLi via 'orderBy' Parameter
Published Oct 11, 2026
·Updated
The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
Affected Software
1 affected component
Paymendo Bank Transfer<=1.1
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated WordPress user, including a user with the Subscriber role or higher, can exploit the SQL injection issue.
2
Which plugin versions are affected?
Paymendo Bank Transfer versions through 1.1 are affected.
3
What input is involved in the attack?
The vulnerable input is the orderBy parameter, which is used in a SQL query without proper sanitization and escaping.