PT-2026-25868 · Unknown+1 · Woocommerce+1

Itthidej Aramsri

+2

·

Publicado

2026-03-17

·

Atualizado

2026-03-17

·

CVE-2026-2579

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress versions up to and including 4.4.3
Description The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is susceptible to SQL Injection via the search parameter. Insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries allow unauthenticated attackers to inject additional SQL queries, potentially extracting sensitive information from the database.
Recommendations Versions prior to 4.4.4 should be updated.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2579

Produtos afetados

Woocommerce
Wowstore – Store Builder & Product Blocks For Woocommerce