CVE-2026-89285
Datalist it <= 0.0.3 - Unauthenticated SQLi via dli_fronted_action
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.
| Vendor | unknown |
| Product | datalist it |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown datalist it
Be the first to know when new unknown vulnerabilities affecting unknown datalist it are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Datalist it
0 โค 0.0.3
References
Credits
Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan