What is CVE-2026-11973?
The WP-Lister Lite for eBay plugin for WordPress up to version 3.8.8 is vulnerable to SQL Injection via the 'orderby' parameter due to insufficient input escaping and query preparation. An unauthenticated attacker could exploit this to extract sensitive data from the database. Users should immediately update the plugin to the latest patched version.
Azərbaycanca: WordPress üçün WP-Lister Lite for eBay plaqininin 3.8.8-ə qədər olan versiyaları 'orderby' parametri vasitəsilə SQL injection zəifliyinə məruz qalır. İstifadəçi tərəfindən təqdim edilən məlumatın yetərsiz filtirlənməsi səbəbindən autentifikasiya olunmamış hücumçu verilənlər bazasından məxfi məlumatları oxuya bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WP-Lister Lite for eBay plugin are affected by the CVE-2026-11973 SQL injection vulnerability?
The vulnerability affects all versions of the plugin up to and including 3.8.8.
What can an attacker achieve by exploiting the CVE-2026-11973 vulnerability?
An unauthenticated attacker can perform SQL Injection to read sensitive data from the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.