CVE-2026-89300
Published 28 September 2026 · tracked since 28 September 2026
Description
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The rout
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-91206 MEDIUM 6.1
- CVE-2026-82382 MEDIUM 6.1
- CVE-2026-82383 HIGH 8.2
- CVE-2026-82384 CRITICAL 9.8
- CVE-2026-82385 MEDIUM 6.5
- CVE-2026-82386 HIGH 7.7
- CVE-2026-82387 MEDIUM 5.4
- CVE-2026-82546 MEDIUM 6.1
- CVE-2026-91204 MEDIUM 6.1
- CVE-2026-82375 HIGH 7.4