The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Yo WordPress plugin versions 1.1 through 1.3.1 contain a critical SQL injection vulnerability in the username request parameter. The plugin fails to sanitize or parameterize user input before incorporating it directly into SQL queries, and critically, it processes this input before WordPress's standard request escaping mechanisms apply. This allows unauthenticated attackers to inject arbitrary SQL commands, potentially exposing the entire WordPress database including sensitive administrator password hashes. Any WordPress site running the affected Yo plugin versions is at immediate risk, with no authentication barrier protecting against exploitation.
When analyzing this vulnerability through Casky's skill framework, practitioners would identify attack patterns aligned with MITRE ATT&CK techniques including T1190 (Exploit Public-Facing Application) and T1005 (Data from Local System). While the specific CVE currently maps to zero Casky skills due to the plugin's niche nature, Claude AI's extended reasoning capabilities would flag the core weakness: improper input validation combined with direct SQL query construction. Security teams using Casky would detect suspicious database query patterns, unauthorized data exfiltration attempts, and anomalous password hash access attempts in their logs—indicators that this SQL injection is being actively exploited to establish initial access and credential harvesting.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-87963. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation