CVE-2026-89285: Datalist it <= 0.0.3 - Unauthenticated SQLi via dli_fronted_action
Published Oct 11, 2026
·Updated
The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.
Affected Software
1 affected component
Datalist it Datalist it WordPress plugin<=0.0.3
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue can be exploited by unauthenticated attackers; no WordPress account or login is required.
2
What is the potential impact of successful exploitation?
An attacker may perform SQL injection and read arbitrary data from the WordPress database.
3
Which plugin versions are affected?
Datalist it WordPress plugin versions through 0.0.3 are affected.