🔐 CVE Alert

CVE-2026-16950

HIGH 8.6

Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products

CVSS Score
8.6
EPSS Score
0.2%
EPSS Percentile
9th

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

Vendor unknown
Product product shortlist
Published Aug 19, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown product shortlist

Be the first to know when new high vulnerabilities affecting unknown product shortlist are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Product Shortlist
0 ≤ 1.0.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/c1a2635a-9919-460f-b662-e5e3f80d2361/

Credits

João Ramos Maciel WPScan