CVE-2026-32459 HIGH

CVE-2026-32459: WordPress UpsellWP plugin <= 2.2.4 - SQL Injection vulnerability

Vendor Flycart
Product UpsellWP
Weakness CWE-89 · SQLi
Published March 13, 2026
Last update April 29, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Blind SQL Injection.This issue affects UpsellWP: from n/a through <= 2.2.4.

Explanation of Vulnerability in Simple Terms

02Summary

UpsellWP versions 2.2.4 and earlier contain a SQL injection vulnerability accessible to high-privilege users. An attacker with admin or equivalent access can inject malicious SQL code through unfiltered input, potentially reading sensitive database records. The vulnerability also impacts site availability. Update to a version newer than 2.2.4.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the site database and cause partial service disruption.

Potential impact on your site

04Site Impact

A compromised admin account could expose customer data, orders, or configuration stored in your database.

Conditions required to exploit

05Prerequisites

Attacker must have high-level admin or equivalent privileges on the site.

Key dates

06Disclosure timeline

March 13, 2026 CVE published
April 29, 2026 Record updated

Related vulnerabilities

08Related CVE