Sceawere

Vulnerability Detail

CVE-2026-89236UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SaveTo Wishlist Lite SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
13h ago
Vendor
Unknown
Product
SaveTo Wishlist Lite
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-03T06:16:45.270Z",
  "pubdate": "2026-10-03T06:16:45.270Z",
  "executiveSummary": "The SaveTo Wishlist Lite WordPress plugin, specifically versions prior to 1.1.5, contains a critical SQL injection vulnerability within its ORDER BY clause implementation.\nThis vulnerability stems from a failure to properly sanitize and escape user-supplied parameters before incorporating them into database queries.\nAn unauthenticated attacker can exploit this flaw to execute arbitrary SQL commands, potentially leading to unauthorized access, modification, or exfiltration of sensitive information stored within the WordPress database.\nGiven that the vulnerability is accessible without authentication, the risk is high, as it allows remote attackers to compromise the integrity and confidentiality of the entire database managed by the affected WordPress installation.\nThe attack complexity is low, making it a highly actionable threat for automated scanning tools and opportunistic attackers targeting vulnerable WordPress deployments.",
  "technicalDetails": "The vulnerability is a classic SQL injection resulting from insecure handling of user input within a SQL query. In the affected versions of the SaveTo Wishlist Lite plugin, user-supplied parameters are directly concatenated into an ORDER BY clause without adequate sanitization or the use of prepared statements.\nThe root cause is the reliance on unsanitized input for dynamic SQL query construction. By manipulating the parameters that dictate the sort order, an attacker can break out of the intended query context and append malicious SQL statements.\nBecause the query is executed via the underlying database interface, the injected SQL commands are processed with the same privileges as the database user configured for the WordPress site.\nAn attacker can exploit this via unauthenticated HTTP requests by injecting specially crafted payloads into the specific URL parameters processed by the vulnerable code. The attack flow generally involves identifying the endpoint that processes user input for sorting, then injecting malicious SQL syntax (such as UNION SELECT statements, time-based blind injection payloads, or stacked queries) to manipulate the query logic.\nThe impact is significant, as successful exploitation allows for the extraction of sensitive database content, including user credentials, configuration data, or private site information. Furthermore, depending on the database configuration, an attacker might be able to modify existing records, insert administrative accounts, or potentially escalate their impact to the server level if the database user possesses excessive privileges.\nThe vulnerability is present in versions before 1.1.5. Since the flaw resides in an unauthenticated endpoint, it is exposed to the public network, requiring no specific user privileges for an attacker to initiate the exploitation process.\nProper remediation requires the application of input validation, sanitization, and the enforcement of parameterized queries (prepared statements) for all database interactions to ensure that user-supplied input is treated strictly as data and never as executable code."
}
CVE-2026-89236: SaveTo Wishlist Lite SQL Injection (HIGH Severity, CVSS: 8.6) | Sceawere