---
id: CVE-2026-89300
title: >-
  The WP Verify API WordPress plugin through 1.0.0 does not have any
  authorisation check in one of its REST routes, allowing unauthenticated users
  to insert arbitrary data into its own database table, as well as to make the
  site send templ…
summary: >-
  The WP Verify API WordPress plugin through 1.0.0 does not have any
  authorisation check in one of its REST routes, allowing unauthenticated users
  to insert arbitrary data into its own database table, as well as to make the
  site send templ…
severity: none
cwe:
  - CWE-862
product: WP Verify API
affected:
  - wp_verify_api <= 1.0.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T07:17:21.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89300'
references:
  - url: 'https://wpscan.com/vulnerability/a5ad8171-83c1-4c2e-83ac-24f008fadb82/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T07:04:53.495Z'
---

## Overview

The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
