CyberRota Analysis
AI-GeneratedThe SaveTo Wishlist Lite WordPress plugin prior to version 1.1.5 is vulnerable due to inadequate sanitization and escaping of parameters in the ORDER BY clause of SQL queries. This flaw allows unauthenticated attackers to execute additional SQL queries, potentially leading to the extraction of sensitive database information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.
Original NVD Description
The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.