Summary
CVE-2026-89236 is an unauthenticated SQL injection vulnerability in the SaveTo Wishlist Lite WordPress plugin, caused by insufficient sanitization and escaping of parameters used in the ORDER BY clause of a SQL query. The flaw affects all plugin versions prior to 1.1.5 and carries a CVSS v3.1 base score of 8.6 (High), allowing remote, unauthenticated attackers to extract sensitive information from the site’s database.
Technical details
- Root cause: the plugin fails to sanitize and escape the
sort_columnandsort_orderparameters before incorporating them into the ORDER BY clause of a SQL query. - Trigger conditions: an attacker sends a crafted request containing malicious values in the
sort_columnand/orsort_orderparameters to a vulnerable endpoint exposed by the plugin. - Attack vector: network-based, requiring no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N).
- Impact: attackers can append additional SQL statements to extract sensitive data from the WordPress database (high confidentiality impact); no direct impact on integrity or availability is indicated by the vector.
Affected software
- SaveTo Wishlist Lite WordPress plugin, all versions before 1.1.5 (i.e., >= 0 and < 1.1.5)
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Update the SaveTo Wishlist Lite plugin to version 1.1.5 or later, which addresses the improper sanitization of the affected parameters.
- If no patch can be applied immediately: restrict or monitor access to the affected plugin endpoints, and deploy a web application firewall rule to filter requests containing SQL metacharacters or anomalous values in
sort_columnandsort_orderparameters until the update can be applied.

