CVE-2026-89300
Received Received - Intake

Unauthenticated Database Injection in WP Verify API WordPress Plugin

Vulnerability report for CVE-2026-89300, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: WPScan

Description

The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_verify_api wp_verify_api to 1.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP Verify API WordPress plugin through version 1.0.0 lacks authorization checks in a REST route. This allows unauthenticated users to insert arbitrary data into the plugin's database table and send templated verification emails to any email address without rate limiting.

Detection Guidance

Check if the WP Verify API plugin version 1.0.0 or below is installed on your WordPress site. Look for unauthorized database entries in the plugin's table or unusual verification emails being sent from your site.

Impact Analysis

An attacker could exploit this to manipulate plugin data or send spam emails from your site. The lack of rate limiting means they could automate these actions, potentially overwhelming your server or damaging your site's reputation.

Compliance Impact

This vulnerability could lead to unauthorized data processing or email transmissions, violating GDPR's data protection principles or HIPAA's integrity requirements. Uncontrolled data insertion may also breach confidentiality obligations.

Mitigation Strategies

Immediately uninstall or disable the WP Verify API plugin until a patch is released. Monitor your site for suspicious activity and restrict access to REST routes if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89300. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart