PT-2025-43726 · WordPress · Product Filter By Wbw+1

Michael Mazzolini

·

Published

2025-10-25

·

Updated

2025-10-30

·

CVE-2025-8416

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Product Filter by WBW versions up to and including 2.9.7
Description The Product Filter by WBW plugin for WordPress is susceptible to SQL Injection via the filtersDataBackend parameter. Insufficient input validation and inadequate SQL query preparation allow attackers to inject additional SQL queries, potentially extracting sensitive information from the database.
Recommendations Update Product Filter by WBW to a version later than 2.9.7

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-8416

Affected Products

Product Filter By Wbw
Wordpress