Impact
The WP Verify API plugin lacks an authorization check on one of its REST endpoints. An unauthenticated attacker can inject arbitrary data into the plugin's database table and trigger the site to send templated verification emails to any e‑mail address supplied by the attacker. This flaw permits data tampering and can be abused for phishing or spamming, compromising the confidentiality and integrity of the site’s communication channel.
Affected Systems
Any WordPress installation running the WP Verify API plugin version 1.0.0 or earlier is affected, as the vulnerability resides in all releases up to that point. No specific vendor or product range beyond the plugin itself is listed.
Risk and Exploitability
The flaw is exploitable through unauthenticated HTTP requests to the vulnerable REST route and there is no rate limiting, so an attacker could repeatedly send emails or modify database content. Because the CVSS score is not available, the risk is assessed as high based on the lack of authentication and the potential for widespread abuse. The vulnerability is not currently listed in CISA’s KEV catalog, and an EPSS score is not available, so exploit probability cannot be precisely quantified, but the straightforward attack vector indicates a considerable risk for active sites.
OpenCVE Enrichment