CVE-2026-16950
EUVD-2026-6227319.08.2026, 06:17
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.