🔐 CVE Alert

CVE-2026-16950

UNKNOWN 0.0

Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

Vendor unknown
Product product shortlist
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown product shortlist

Be the first to know when new unknown vulnerabilities affecting unknown product shortlist are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Product Shortlist
0 ≤ 1.0.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/c1a2635a-9919-460f-b662-e5e3f80d2361/

Credits

João Ramos Maciel WPScan