PatchSiren

WP Verify API CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review WP Verify API CVE published 2026-09-28

CVE-2026-89300

CVE-2026-89300 debrief based on the supplied source corpus. The CVE record was published on 2026-09-28T07:17:21.180Z and has not been modified since then. The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verificatio [truncated]