CVE-2026-3830

CVE-2026-3830: Product Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQLi

Vendor Unknown
Product Product Filter for WooCommerce by WBW
Published April 13, 2026
Last update April 13, 2026

CVSS base score

What the vulnerability does

Description

The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

Key dates

Disclosure timeline

April 13, 2026 CVE published
April 13, 2026 Record updated