๐Ÿ” CVE Alert

CVE-2026-89285

UNKNOWN 0.0

Datalist it <= 0.0.3 - Unauthenticated SQLi via dli_fronted_action

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.

Vendor unknown
Product datalist it
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown datalist it

Be the first to know when new unknown vulnerabilities affecting unknown datalist it are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Datalist it
0 โ‰ค 0.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/27135434-79e0-4f9e-aecf-c7092faec29b/

Credits

Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan