Skip to main content
Vulnerability Database/CVE-2026-89236

CVE-2026-89236: SaveTo Wishlist Lite SQL Injection Flaw

CVE-2026-89236 is a SQL injection vulnerability in SaveTo Wishlist Lite WordPress plugin that allows unauthenticated attackers to extract sensitive database information. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-89236 Overview

CVE-2026-89236 is a SQL injection vulnerability in the SaveTo Wishlist Lite WordPress plugin before version 1.1.5. The plugin fails to sanitize and escape user-supplied parameters before using them in the ORDER BY clause of a SQL query. Unauthenticated attackers can append arbitrary SQL to extract sensitive data from the WordPress database. The flaw is classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).

Critical Impact

Unauthenticated remote attackers can exfiltrate database contents, including user credentials, session tokens, and sensitive customer data stored by WordPress and related plugins.

Affected Products

  • SaveTo Wishlist Lite WordPress plugin versions prior to 1.1.5
  • WordPress sites running the vulnerable plugin with public-facing endpoints
  • E-commerce deployments integrating the wishlist functionality

Discovery Timeline

  • 2026-10-03 - CVE-2026-89236 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-89236

Vulnerability Analysis

The vulnerability resides in a plugin endpoint that accepts a sortable parameter and interpolates it directly into a SQL ORDER BY clause. Because parameterized queries cannot bind column names or sort directions, developers must enforce an allow-list before composing the query. SaveTo Wishlist Lite skips this validation and passes attacker-controlled input straight into the SQL statement.

An unauthenticated attacker can abuse this flaw to append subqueries, perform UNION-based extraction, or use time-based blind techniques. Because exploitation requires no authentication and no user interaction, any publicly reachable WordPress site running a vulnerable version is at risk.

Root Cause

The root cause is missing input sanitization and the absence of a strict allow-list for ORDER BY values. WordPress provides the sanitize_sql_orderby() helper and the $wpdb->prepare() API, but neither is applied to the affected parameter. Attacker input flows unmodified into the query string.

Attack Vector

Exploitation occurs over the network via HTTP requests to the plugin's query endpoint. The attacker supplies a malicious value in the parameter used for sorting. The injected SQL executes with the privileges of the WordPress database user, which typically has full read and write access to the wp_* tables. Further technical details are published in the WPScan Vulnerability Report.

Detection Methods for CVE-2026-89236

Indicators of Compromise

  • HTTP requests containing SQL keywords such as UNION, SELECT, SLEEP(, or BENCHMARK( in the sort or order parameters of wishlist endpoints
  • Unusual response times for wishlist-related requests indicating time-based blind SQL injection
  • Web server access logs showing repeated requests from a single source enumerating database schema data
  • Outbound queries to information_schema.tables or wp_users originating from the plugin context

Detection Strategies

  • Deploy a web application firewall rule set to flag SQL metacharacters in request parameters bound for the vulnerable plugin
  • Enable MySQL general query logging on affected hosts and alert on unexpected UNION SELECT statements
  • Review WordPress plugin inventory for saveto-wishlist-lite versions below 1.1.5

Monitoring Recommendations

  • Baseline normal query patterns for the plugin and alert on deviations such as abnormally long queries
  • Monitor authentication logs for subsequent credential-based logins following suspicious wishlist traffic
  • Track egress volume from the database server to identify bulk data exfiltration

How to Mitigate CVE-2026-89236

Immediate Actions Required

  • Upgrade SaveTo Wishlist Lite to version 1.1.5 or later on all WordPress installations
  • Audit WordPress and database logs for signs of prior exploitation targeting wishlist endpoints
  • Rotate database credentials and WordPress secret keys if evidence of compromise exists
  • Restrict public access to administrative and non-essential plugin endpoints via WAF rules

Patch Information

The vendor addressed the issue in SaveTo Wishlist Lite version 1.1.5 by sanitizing the affected parameter before use in the SQL ORDER BY clause. Site administrators should apply the update through the WordPress plugin dashboard or via WP-CLI. Confirm the installed version after update using wp plugin list --name=saveto-wishlist-lite.

Workarounds

  • Temporarily deactivate the SaveTo Wishlist Lite plugin until the patched version is deployed
  • Implement a WAF signature that blocks SQL metacharacters in the vulnerable parameter
  • Enforce least-privilege permissions on the WordPress database user to limit the impact of injection
bash
# Update the plugin via WP-CLI
wp plugin update saveto-wishlist-lite --version=1.1.5

# Verify installed version
wp plugin list --name=saveto-wishlist-lite --fields=name,status,version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.