CyberRota Analysis
AI-GeneratedThe Product Shortlist plugin for WordPress, up to version 1.0.4, is vulnerable to SQL injection due to improper sanitization and escaping of user-supplied parameters in SQL statements. This flaw allows unauthenticated attackers to execute arbitrary SQL queries, potentially compromising the database and exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to a patched version to mitigate the risk of exploitation.
Original NVD Description
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.