Description
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
Published: 2026-09-17
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Read arbitrary database data including administrator password hashes
Action: Immediate Patch
AI Analysis

Impact

Untrusted input from the username request parameter is incorporated directly into an SQL query by the Yo plugin (versions 1.1 through 1.3.1) without sanitization or parameterization. This flaw enables SQL injection, allowing an attacker to read any table in the WordPress database, including password hash columns, thus compromising credential confidentiality and potentially leading to further compromise.

Affected Systems

The vulnerability affects the Yo WordPress plugin across all releases from version 1.1 up to 1.3.1. The vendor is not specified beyond the general "Yo" label, and no specific WordPress core or operating system versions are listed, so any WordPress installation hosting these plugin versions is affected.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score is below 1%, suggesting that exploitation is currently unlikely, but the lack of KEV listing does not eliminate the risk. Attackers can trigger the vulnerability simply by sending an unauthenticated HTTP request to the plugin’s endpoint that contains the username parameter, and the injection can be used to extract arbitrary data, especially passwords. Based on the potential for credential compromise, it is inferred that an attacker could use those credentials to cause outages, exfiltrate data, or pivot to other systems, but these specific outcomes are not explicitly documented in the CVE description.

Generated by OpenCVE AI on September 18, 2026 at 02:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Yo plugin to a version newer than 1.3.1 or remove it entirely if it is no longer needed.
  • If an update is not immediately possible, block unauthenticated access to the plugin’s request endpoint using a web‑application firewall or access‑control settings, ensuring only privileged users can send the username parameter.
  • Implement or enforce input validation for the username field by adding a patch that sanitizes or parameterizes the SQL query, or disable the vulnerable feature until a vendor fix is available.

Generated by OpenCVE AI on September 18, 2026 at 02:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions yo
Vendors & Products Wordpress-extensions
Wordpress-extensions yo

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-89

Thu, 17 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
Title Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Wordpress-extensions Yo
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:52:50.199Z

Reserved: 2026-09-09T17:43:52.721Z

Link: CVE-2026-87963

cve-icon Vulnrichment

Updated: 2026-09-17T12:07:45.556Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T07:16:28.533

Modified: 2026-09-20T14:16:59.507

Link: CVE-2026-87963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:40Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')