What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW woo-product-filter allows SQL Injection.This issue affects Product Filter by WBW: from n/a through <= 2.7.0.
Explanation of Vulnerability in Simple Terms
02Summary
Product Filter by WBW versions 2.7.0 and earlier contain a SQL injection vulnerability accessible to high-privilege users. An attacker with admin or equivalent access can inject malicious SQL through the plugin's filter functionality, potentially reading sensitive database contents and disrupting site availability. The vulnerability requires administrative credentials to exploit.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site's database and cause service disruption.
Potential impact on your site
04Site Impact
An admin account compromise could expose your database contents and cause the site to become unstable or unavailable.
Conditions required to exploit
05Prerequisites
Attacker must have high-level admin or equivalent privileges on the WordPress site.
Key dates
06Disclosure timeline
October 24, 2024
CVE published
May 11, 2026
Record updated