SQL Injection Vulnerability in SaveTo Wishlist Lite Plugin by WordPress
CVE-2026-89236

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-89236?

The SaveTo Wishlist Lite plugin for WordPress prior to version 1.1.5 contains a security vulnerability that allows unauthenticated attackers to inject malicious SQL code through unsanitized parameters in the ORDER BY clause. This flaw permits attackers to execute arbitrary SQL queries, leading to potential exposure and extraction of sensitive database information. Website administrators should update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

SaveTo Wishlist Lite 0 < 1.1.5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naoki Kawahigashi
WPScan
.