Description
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
Published: 2026-09-28
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated data injection and arbitrary email dispatch
Action: Apply Patch
AI Analysis

Impact

The WP Verify API plugin lacks an authorization check on one of its REST endpoints. An unauthenticated attacker can inject arbitrary data into the plugin's database table and trigger the site to send templated verification emails to any e‑mail address supplied by the attacker. This flaw permits data tampering and can be abused for phishing or spamming, compromising the confidentiality and integrity of the site’s communication channel.

Affected Systems

Any WordPress installation running the WP Verify API plugin version 1.0.0 or earlier is affected, as the vulnerability resides in all releases up to that point. No specific vendor or product range beyond the plugin itself is listed.

Risk and Exploitability

The flaw is exploitable through unauthenticated HTTP requests to the vulnerable REST route and there is no rate limiting, so an attacker could repeatedly send emails or modify database content. Because the CVSS score is not available, the risk is assessed as high based on the lack of authentication and the potential for widespread abuse. The vulnerability is not currently listed in CISA’s KEV catalog, and an EPSS score is not available, so exploit probability cannot be precisely quantified, but the straightforward attack vector indicates a considerable risk for active sites.

Generated by OpenCVE AI on September 28, 2026 at 07:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Verify API plugin to the latest vendor release that includes a fix for the authorization check.
  • If no update is immediately available, block or protect the /wp-json/wp-verify-api/* endpoint against unauthenticated requests, or enforce authentication through plugin settings or a firewall rule.
  • Continuously monitor outbound email logs for unexpected verification messages and apply email filtering rules to detect or quarantine spoofed verification emails.

Generated by OpenCVE AI on September 28, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-89

Mon, 28 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
Title WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-28T06:00:19.338Z

Reserved: 2026-09-11T13:18:08.696Z

Link: CVE-2026-89300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T07:17:21.180

Modified: 2026-09-28T07:17:21.180

Link: CVE-2026-89300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T07:30:17Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')