SQL Injection Vulnerability in WP-Lister Lite for eBay Plugin by WordPress
CVE-2026-11973
4.9MEDIUM
What is CVE-2026-11973?
The WP-Lister Lite for eBay plugin for WordPress is exposed to an SQL injection flaw via the 'orderby' parameter. This vulnerability stems from inadequate input validation and escaping practices in user-supplied parameters, allowing authenticated users with administrator access to manipulate existing SQL queries. By appending unauthorized SQL commands, these attackers could extract sensitive information from the database, posing a significant risk to the integrity and confidentiality of data stored within WordPress sites using this plugin.
Affected Version(s)
WP-Lister Lite for eBay 0 <= 3.8.8