Feed/CVE-2026-16950
CVE-2026-16950

CVE-2026-16950

Published Aug 19, 2026·Updated Aug 19, 2026

NVD Description

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free