rootpwn

high · CVSS v3 8.6 · EPSS 0.00172

CVE-2026-89236

The SaveTo Wishlist Lite WordPress plugin (v<1.1.5) contains an unsanitized ORDER BY clause that allows unauthenticated attackers to inject

Overview

The SaveTo Wishlist Lite WordPress plugin (v<1.1.5) contains an unsanitized ORDER BY clause that allows unauthenticated attackers to inject SQL and exfiltrate database data. This flaw can be exploited without authentication, exposing sensitive content. The vulnerability is rated high severity with a CVSS v3 score of 8.6.

Description

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

Impact

Confidentiality: attackers can read private database tables. Integrity: malicious queries could modify data. Availability: repeated injections may degrade performance. Defenders should treat this as a critical data exposure risk.

Remediation

Update the plugin to version 1.1.5 or later. If update is not possible, disable the plugin or restrict its database permissions. Implement input validation and use parameterized queries. Monitor database logs for suspicious ORDER BY patterns.

Risk context

Severity is high (CVSS 8.6) but EPSS is very low (0.00172), indicating limited current exploitation. Nonetheless, the flaw remains exploitable and should be patched promptly.

Affected products

  • WordPress
  • SaveTo Wishlist Lite

Scores

Severity
high
CVSS v2
7.8
CVSS v3
8.6
CVSS v4
—
EPSS
0.00172

sql-injection wordpress plugin database high-severity EPSS-low

← All CVEs