CVE-2026-89234
WP-Partner <= 1.2.1 - Unauthenticated SQLi via 'id' Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
| Vendor | unknown |
| Product | wp-partner |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp-partner
Be the first to know when new unknown vulnerabilities affecting unknown wp-partner are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Unknown / WP-Partner
0 β€ 1.2.1
References
Credits
RaΓΊl Conesa WPScan