{"id":"CVE-2026-89235","title":"The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.","summary":"The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-89"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:19.660","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89235","references":[{"url":"https://wpscan.com/vulnerability/00801815-efc8-41f7-9984-0e81698c7f68/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T12:53:29.334Z","slug":"CVE-2026-89235","body":"## Overview\n\nThe Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}