The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either. | |
| Title | WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-28T06:00:19.338Z
Reserved: 2026-09-11T13:18:08.696Z
Link: CVE-2026-89300
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.