PatchSiren

Datalist it CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Datalist it CVE published 2026-10-11

CVE-2026-89285

The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database. This SQL injection vulnerability in the Datalist it WordPress plugin allows unauthenticated attackers to read arbitrary data from the database, potentially leadin [truncated]