CVE-2026-89236
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 03, 2026
Vendor
unknown
Description
The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.