---
id: CVE-2026-89236
title: >-
  The SaveTo Wishlist Lite  WordPress plugin before 1.1.5 does not sanitise and
  escape parameters before using them in the ORDER BY clause of a SQL query,
  allowing unauthenticated attackers to append additional SQL queries and
  extract sens…
summary: >-
  The SaveTo Wishlist Lite  WordPress plugin before 1.1.5 does not sanitise and
  escape parameters before using them in the ORDER BY clause of a SQL query,
  allowing unauthenticated attackers to append additional SQL queries and
  extract sens…
severity: none
cwe:
  - CWE-89
product: SaveTo Wishlist Lite
affected:
  - saveto_wishlist_lite < 1.1.5
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:45.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89236'
references:
  - url: 'https://wpscan.com/vulnerability/7b92ed60-7bcb-4dcf-8c57-0afcaa6809b7/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.566Z'
---

## Overview

The SaveTo Wishlist Lite  WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
