CVE-2026-16950
Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
| Vendor | unknown |
| Product | product shortlist |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown product shortlist
Be the first to know when new unknown vulnerabilities affecting unknown product shortlist are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Product Shortlist
0 ≤ 1.0.4
References
Credits
João Ramos Maciel WPScan