OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-89236

HIGH · CVSS 8.6 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The SaveTo Wishlist Lite WordPress plugin prior to version 1.1.5 is vulnerable due to inadequate sanitization and escaping of parameters in the ORDER BY clause of SQL queries. This flaw allows unauthenticated attackers to execute additional SQL queries, potentially leading to the extraction of sensitive database information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-89236
Severity
HIGH
CVSS
8.6
EPSS
0.27%
WordPress

Original NVD Description

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.