VYPR

paymendo

by WordPress

CVEs (2)

  • CVE-2026-89305Oct 11, 2026
    risk 0.00cvss —epss —

    The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.

  • CVE-2026-89304Oct 11, 2026
    risk 0.00cvss —epss —

    The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform blind SQL injection attacks.