CVE-2026-66628: WordPress WP-Lister Lite for eBay plugin <= 3.8.11 - SQL Injection vulnerability
Published Sep 17, 2026
·Updated
Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
Affected Software
1 affected component
WordPress WP-Lister Lite for eBay plugin<=3.8.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP-Lister Lite for eBay pluginto a version that resolves this vulnerability.Fixed in 3.8.12
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs shop manager privileges in WordPress. The vulnerability is remotely reachable, requires no user interaction, and has low attack complexity.
2
What impact could successful exploitation have?
Successful SQL injection can expose confidential data and cause limited availability impact. The CVSS vector indicates no direct integrity impact, but the scope may extend beyond the vulnerable component.
3
Which plugin versions are affected?
WP-Lister Lite for eBay versions up to and including 3.8.11 are affected.