Sceawere
Vulnerability Detail
CVE-2026-89299UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Verify API SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- WP Verify API
- Attack Type
- CWE-89 SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WP Verify API WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-11T07:17:28.770Z",
"pubdate": "2026-10-11T07:17:28.770Z",
"executiveSummary": "The WP Verify API WordPress plugin, specifically version 1.0.0 and below, contains a critical SQL injection vulnerability.\nThis vulnerability exists due to the application's failure to sanitize and escape user-supplied input before incorporating it into database queries.\nSuccessful exploitation allows unauthenticated remote attackers to interact directly with the underlying WordPress database.\nThe impact includes unauthorized data exposure, potential modification of administrative records, or complete compromise of the site's data integrity.\nAs an unauthenticated vulnerability, it requires no specific user privileges or access levels, posing a significant risk to affected WordPress installations.\nAttackers can leverage this flaw to extract sensitive information, such as user credentials, configuration settings, or private data, by injecting malicious SQL commands via affected parameters.",
"technicalDetails": "The vulnerability is rooted in improper input validation and the absence of prepared statements or parameterized queries within the affected code paths of the WP Verify API plugin.\nWhen the plugin processes user-supplied data, it passes the raw input directly into a database query string. Because the application fails to utilize sanitization functions (such as esc_sql() or $wpdb->prepare()) to neutralize special characters, an attacker can manipulate the query structure.\nThe attack flow begins when an attacker identifies an input parameter that is concatenated directly into a SQL statement. By injecting crafted SQL syntax, the attacker can break out of the intended query context and append arbitrary SQL commands, such as UNION SELECT statements or blind SQL injection payloads.\nSince the affected component does not implement access control checks for this operation, the vulnerability is accessible to unauthenticated remote attackers via HTTP requests.\nThe exploitation allows for the alteration of the query's logic, enabling the attacker to retrieve data from arbitrary tables within the database schema. This may include the wp_users table, potentially leading to the extraction of hashed passwords or privilege escalation.\nThe lack of prepared statements allows the database engine to interpret the injected payload as part of the command execution, granting the attacker control over the interaction with the database. This effectively bypasses standard web application security boundaries.\nThe vulnerability persists in version 1.0.0 and all preceding versions, as no mechanisms exist to intercept and sanitize the malicious input prior to execution.\nPost-exploitation impact is limited only by the permissions of the database user configured for the WordPress site, though it is common for the database user to have sufficient privileges to perform unauthorized data modifications or administrative actions within the scope of the plugin's environment."
}