CVE-2026-89236 Overview
CVE-2026-89236 is a SQL injection vulnerability in the SaveTo Wishlist Lite WordPress plugin before version 1.1.5. The plugin fails to sanitize and escape user-supplied parameters before using them in the ORDER BY clause of a SQL query. Unauthenticated attackers can append arbitrary SQL to extract sensitive data from the WordPress database. The flaw is classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).
Critical Impact
Unauthenticated remote attackers can exfiltrate database contents, including user credentials, session tokens, and sensitive customer data stored by WordPress and related plugins.
Affected Products
- SaveTo Wishlist Lite WordPress plugin versions prior to 1.1.5
- WordPress sites running the vulnerable plugin with public-facing endpoints
- E-commerce deployments integrating the wishlist functionality
Discovery Timeline
- 2026-10-03 - CVE-2026-89236 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-89236
Vulnerability Analysis
The vulnerability resides in a plugin endpoint that accepts a sortable parameter and interpolates it directly into a SQL ORDER BY clause. Because parameterized queries cannot bind column names or sort directions, developers must enforce an allow-list before composing the query. SaveTo Wishlist Lite skips this validation and passes attacker-controlled input straight into the SQL statement.
An unauthenticated attacker can abuse this flaw to append subqueries, perform UNION-based extraction, or use time-based blind techniques. Because exploitation requires no authentication and no user interaction, any publicly reachable WordPress site running a vulnerable version is at risk.
Root Cause
The root cause is missing input sanitization and the absence of a strict allow-list for ORDER BY values. WordPress provides the sanitize_sql_orderby() helper and the $wpdb->prepare() API, but neither is applied to the affected parameter. Attacker input flows unmodified into the query string.
Attack Vector
Exploitation occurs over the network via HTTP requests to the plugin's query endpoint. The attacker supplies a malicious value in the parameter used for sorting. The injected SQL executes with the privileges of the WordPress database user, which typically has full read and write access to the wp_* tables. Further technical details are published in the WPScan Vulnerability Report.
Detection Methods for CVE-2026-89236
Indicators of Compromise
- HTTP requests containing SQL keywords such as UNION, SELECT, SLEEP(, or BENCHMARK( in the sort or order parameters of wishlist endpoints
- Unusual response times for wishlist-related requests indicating time-based blind SQL injection
- Web server access logs showing repeated requests from a single source enumerating database schema data
- Outbound queries to information_schema.tables or wp_users originating from the plugin context
Detection Strategies
- Deploy a web application firewall rule set to flag SQL metacharacters in request parameters bound for the vulnerable plugin
- Enable MySQL general query logging on affected hosts and alert on unexpected UNION SELECT statements
- Review WordPress plugin inventory for saveto-wishlist-lite versions below 1.1.5
Monitoring Recommendations
- Baseline normal query patterns for the plugin and alert on deviations such as abnormally long queries
- Monitor authentication logs for subsequent credential-based logins following suspicious wishlist traffic
- Track egress volume from the database server to identify bulk data exfiltration
How to Mitigate CVE-2026-89236
Immediate Actions Required
- Upgrade SaveTo Wishlist Lite to version 1.1.5 or later on all WordPress installations
- Audit WordPress and database logs for signs of prior exploitation targeting wishlist endpoints
- Rotate database credentials and WordPress secret keys if evidence of compromise exists
- Restrict public access to administrative and non-essential plugin endpoints via WAF rules
Patch Information
The vendor addressed the issue in SaveTo Wishlist Lite version 1.1.5 by sanitizing the affected parameter before use in the SQL ORDER BY clause. Site administrators should apply the update through the WordPress plugin dashboard or via WP-CLI. Confirm the installed version after update using wp plugin list --name=saveto-wishlist-lite.
Workarounds
- Temporarily deactivate the SaveTo Wishlist Lite plugin until the patched version is deployed
- Implement a WAF signature that blocks SQL metacharacters in the vulnerable parameter
- Enforce least-privilege permissions on the WordPress database user to limit the impact of injection
# Update the plugin via WP-CLI
wp plugin update saveto-wishlist-lite --version=1.1.5
# Verify installed version
wp plugin list --name=saveto-wishlist-lite --fields=name,status,version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.