VYPR

SaveTo Wishlist Lite

by WordPress

CVEs (1)

  • CVE-2026-89236Oct 3, 2026
    risk 0.00cvss —epss —

    The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.