CVE-2026-16950
Product Shortlist
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
- CVSS
- 8.6
- EPSS
- 0.32% 25.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.19