MEDIUM 5.3 NVD

CVE-2026-89300

The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbit

The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.

References

Published: 2026-09-28 · Source: NVD · Feed updated: 2026-09-28
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-28 via NVD.
vulnfeed aggregates 13625 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.