VYPR

WP-Partner

by WordPress

CVEs (1)

  • CVE-2026-89234Oct 11, 2026
    risk 0.00cvss —epss —

    The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.