SQL Injection Vulnerability in Pro Like Button Plugin for WordPress
CVE-2026-89296
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 October 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-89296?
The Pro Like Button plugin for WordPress prior to version 2.0 contains a vulnerability that fails to properly sanitize and escape input parameters used in SQL queries. This flaw allows unauthenticated attackers to manipulate the queries, potentially executing arbitrary SQL commands. As a result, sensitive database information may be exfiltrated or corrupted, putting user data and site integrity at risk.
Affected Version(s)
Pro Like Button 0 < 2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.