CVE-2026-89300
WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
| Vendor | unknown |
| Product | wp verify api |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp verify api
Be the first to know when new unknown vulnerabilities affecting unknown wp verify api are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Verify API
0 โค 1.0.0
References
Credits
RIA Labs WPScan