Security Alert Summary
The Testimonials by BestWebSoft WordPress plugin through 1.0.8 contains an SQL injection vulnerability. An unauthenticated attacker can append additional SQL to a query because a parameter is not sanitised and escaped before being used in a database query. This can expose confidential data stored in the site database.
CVE Details
- CVE ID: CVE-2026-89235
- Affected component: Testimonials by BestWebSoft WordPress plugin
- Affected versions: Versions 1.0.5 through 1.0.8 (inclusive)
- Published: October 9, 2026 at 12:17:12 PM UTC
- Last modified: October 9, 2026 at 03:17:19 PM UTC
- CVSS v3.1: Base score 6.8 – MEDIUM; Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
- Authentication / privileges / user interaction: No authentication required; Privileges required: None; User interaction: None; Attack complexity: High; Scope: Changed
- Primary impact: Confidentiality: High; Integrity: None; Availability: None
- Other metrics: Exploitability score 2.2; Impact score 4.0 (from CVSS metric data). SSVC options indicate exploitation: none; automatable: no; technical impact: partial.
- CWE: CWE-89 (SQL Injection)
Technical Details
The plugin fails to sanitise and escape a parameter before incorporating it into a SQL query, which results in an SQL injection vulnerability. Because the vulnerable parameter is usable without authentication, an attacker can append additional SQL to the query sent to the database.
The description does not name specific functions or REST endpoints. Based on the provided information, the root cause is missing input sanitisation and escaping for a user-controllable parameter prior to database usage.
Impact is limited to confidentiality according to the CVSS data: an attacker could retrieve sensitive data from the database but the available data indicates no direct ability to modify data or disrupt availability through this issue.
How This Could Impact Your Website
Consider a site with multiple WordPress users: the site owner, internal staff who manage content, and external contractors or contributors. An unauthenticated attacker exploiting this SQL injection could extract confidential information from the database, including internal user details or other stored records.
Practical consequences include exposure of internal user email addresses and other stored data, which increases the risk of targeted phishing or social engineering campaigns against staff or contractors. The issue does not, based on the provided data, indicate direct modification of content or full site takeover, but the disclosure of confidential data can still have operational and reputational consequences.
If youre unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Temporarily disable the plugin if you believe your site is exposed and a patch is not yet available.
- Review and reduce unnecessary user roles, especially contributors and other low-trust accounts.
- Enforce strong passwords and enable two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins from your site.
- Monitor site activity and database access logs for unusual behavior that could indicate exploitation.
If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.