Review
Datalist it
CVE published 2026-10-11
CVE-2026-89285
The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database. This SQL injection vulnerability in the Datalist it WordPress plugin allows unauthenticated attackers to read arbitrary data from the database, potentially leadin [truncated]