VYPR

Product Shortlist

by WordPress

CVEs (1)

  • CVE-2026-16950Aug 19, 2026
    risk 0.00cvss epss

    The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.