PT-2026-65726 · WordPress · Wp-Lister Lite For Ebay
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP-Lister Lite for eBay versions prior to 3.8.9
Description
The WP-Lister Lite for eBay plugin for WordPress contains a generic SQL Injection flaw. This occurs because the software fails to properly escape user-supplied input and lacks sufficient preparation of the SQL query. Authenticated attackers with administrator-level access or higher can exploit this by appending malicious SQL queries to existing ones via the
orderby parameter to extract sensitive information from the database.Recommendations
Update WP-Lister Lite for eBay to version 3.8.9 or later.
As a temporary mitigation, restrict access to the
orderby parameter for administrative users until the update is applied.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp-Lister Lite For Ebay