CVE-2026-89235: Unknown Testimonials By Bestwebsoft
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.
Affected products
- Unknown Testimonials By Bestwebsoft: from 1.0.5, up to and including 1.0.8
Published 2026-10-09. Last modified 2026-10-09.