CVE-2026-89235
MEDIUM
NVD
CVSS Score
6.8
Severity
MEDIUM
Published
Oct 09, 2026
Vendor
unknown
Description
The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.