Executive brief
WP-Lister Lite for eBay is a WordPress plugin that enables sellers to manage and list products on eBay directly from their website. A SQL injection vulnerability in the plugin's shop manager functionality allows authenticated attackers with the shop manager role to read, modify, or delete the website's entire database, including user accounts and sensitive customer data.
Technical details
This is a SQL injection vulnerability in WP-Lister Lite for eBay that requires shop manager privileges to exploit. The vulnerable component fails to properly sanitize user input before constructing SQL queries. An authenticated shop manager can inject arbitrary SQL commands through the affected functionality, allowing them to extract sensitive data, modify database contents, or execute administrative database operations. The vulnerability affects versions up to and including 3.8.11, and patches are available in version 3.8.12 and later.
Affected products
- WP Lab WP-Lister Lite for eBay <=3.8.11
Timeline
- 2026-09-17: disclosed: CVE-2026-66628 published
- 2026-09-17: patched: Fix available in version 3.8.12