CVE-2026-89305
Received Received - Intake

SQL Injection in Paymendo WordPress Plugin

Vulnerability report for CVE-2026-89305, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown paymendo 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability is a SQL injection flaw in the Paymendo WordPress plugin version 1.1 or below. It occurs because the plugin fails to properly sanitize and escape the 'orderBy' parameter before using it in a SQL query. This allows any authenticated user, even with basic subscriber access, to inject malicious SQL code into the database.

Detection Guidance

To detect this vulnerability, check if the Paymendo WordPress plugin version 1.1 or below is installed. Inspect the plugin's code for improper sanitization of the 'orderBy' parameter in SQL queries. Use WPScan or similar tools to scan for vulnerable plugins.

Impact Analysis

This vulnerability can allow attackers to manipulate your WordPress database, potentially stealing sensitive data like user credentials, payment information, or other confidential details. Attackers could also modify or delete database contents, leading to site defacement or complete site compromise.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by exposing personal or health data. GDPR requires protection of personal data, and HIPAA mandates safeguards for health information. A breach could result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Immediately update the Paymendo plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Restrict database access permissions for WordPress users to limit potential damage from SQL injection.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89305. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart