PatchSiren

SaveTo Wishlist Lite CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review SaveTo Wishlist Lite CVE published 2026-10-03

CVE-2026-89236

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. This vulnerability affects WordPress installations with the SaveTo Wishlist Lite plugin, potentially leading to SQL injection attacks a [truncated]