CVE-2026-89236: Unknown Saveto Wishlist Lite

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

Affected products

  • Unknown Saveto Wishlist Lite: before 1.1.5 (fixed in 1.1.5)

Published 2026-10-03. Last modified 2026-10-06.