PatchSiren

WP-Partner CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review WP-Partner CVE published 2026-10-11

CVE-2026-89234

CVE-2026-89234 is a SQL injection vulnerability in the WP-Partner WordPress plugin through version 1.2.1. The plugin does not sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. This vulnerability can have significant impacts on database integrity and confidentiality. Defend [truncated]