What is CVE-2026-16950?
This vulnerability exists in "The Product Shortlist" WordPress plugin up to version 1.0.4. The plugin does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks. It is recommended to update the plugin to the latest version or temporarily deactivate it.
Azərbaycanca: Bu boşluq "The Product Shortlist" WordPress plugin-inin 1.0.4-ə qədər olan versiyalarında mövcuddur. Plaqin bir parametri SQL sorğusunda istifadə etməzdən əvvəl düzgün təmizləmədiyi üçün autentifikasiya olunmamış hücumçulara SQL injection hücumları həyata keçirməyə imkan verir. Plaqini ən son versiyaya yeniləmək və ya müvəqqəti olaraq deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-16950?
This vulnerability affects "The Product Shortlist" WordPress plugin.
What is recommended to protect against CVE-2026-16950?
It is recommended to update the plugin to the latest version or temporarily deactivate it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.