PatchSiren

Yo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Yo CVE published 2026-09-17

CVE-2026-87963

The Yo WordPress plugin, versions 1.1 through 1.3.1, is vulnerable to SQL injection attacks due to improper sanitization of the username request parameter. This allows unauthenticated attackers to read arbitrary database contents, including administrator password hashes. The vulnerability requires immediate attention from WordPress administrators and security teams to prevent potential unauthorized access [truncated]