Executive brief
The Yo WordPress plugin is a community extension that adds functionality to WordPress websites. Versions 1.1 through 1.3.1 contain a critical flaw that allows unauthenticated attackers to execute SQL injection attacks without requiring login credentials. An attacker can exploit this vulnerability to read sensitive database contents, including administrator password hashes, which could lead to full compromise of affected WordPress sites.
Technical details
The Yo WordPress plugin versions 1.1 through 1.3.1 contain an unauthenticated SQL injection vulnerability in the handling of the username request parameter. The vulnerable code reads and uses the username parameter directly in a SQL query without proper sanitization or parameterization, and processes it before WordPress applies its standard request escaping mechanisms. This allows an unauthenticated attacker to inject arbitrary SQL commands via the username parameter to extract sensitive data from the WordPress database, including administrator password hashes. No official patch has been announced as of the advisory date; users should update to a patched version once available or disable the plugin.
Affected products
- Yo 1.1 through 1.3.1
Timeline
- 2026-09-15: disclosed
- 2026-09-17: advisory