SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16950

HIGH · CVSS 8.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Product Shortlist plugin for WordPress, up to version 1.0.4, is vulnerable to SQL injection due to improper sanitization and escaping of user-supplied parameters in SQL statements. This flaw allows unauthenticated attackers to execute arbitrary SQL queries, potentially compromising the database and exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to a patched version to mitigate the risk of exploitation.

CVE
CVE-2026-16950
Severity
HIGH
CVSS
8.6
EPSS
0.32%
WordPress

Original NVD Description

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.