CVE-2026-89300 - WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients
CVE ID :CVE-2026-89300
Published : Sept. 28, 2026, 6 a.m. | 1 hour, 12 minutes ago
Description :The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 28, 2026, 6 a.m. | 1 hour, 12 minutes ago
Description :The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...