HIGH
Yo
CVE published 2026-09-17
CVE-2026-87963
The Yo WordPress plugin, versions 1.1 through 1.3.1, is vulnerable to SQL injection attacks due to improper sanitization of the username request parameter. This allows unauthenticated attackers to read arbitrary database contents, including administrator password hashes. The vulnerability requires immediate attention from WordPress administrators and security teams to prevent potential unauthorized access [truncated]