CVE-2026-89236
SaveTo Wishlist Lite < 1.1.5 - Unauthenticated SQLi via 'sort_column' and 'sort_order' Parameters
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
| Vendor | unknown |
| Product | saveto wishlist lite |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown saveto wishlist lite
Be the first to know when new unknown vulnerabilities affecting unknown saveto wishlist lite are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / SaveTo Wishlist Lite
0 < 1.1.5
References
Credits
Naoki Kawahigashi WPScan