You're viewing a limited, public preview. Log in for full access.
Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products
No AI analysis yet.
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
This link opens an external site that isn't part of the platform.