Review
SaveTo Wishlist Lite
CVE published 2026-10-03
CVE-2026-89236
The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. This vulnerability affects WordPress installations with the SaveTo Wishlist Lite plugin, potentially leading to SQL injection attacks a [truncated]