CVE-2026-32554

9.3

WBW · WooBeWoo Product Filter Pro

An unauthenticated SQL injection vulnerability in the WooBeWoo Product Filter Pro plugin up to version 3.1.8 allows attackers to execute arbitrary database queries.

Executive summary

The WBW WooBeWoo Product Filter Pro plugin contains a critical SQL injection vulnerability that allows unauthenticated attackers to compromise database integrity.

Vulnerability

This is an SQL injection vulnerability (CWE-89) affecting the plugin, which fails to properly sanitize user-supplied input before processing database queries. The vulnerability is exploitable by unauthenticated remote attackers.

Business impact

Successful exploitation allows an attacker to interact directly with the underlying database, potentially leading to unauthorized data disclosure, modification, or deletion. With a CVSS score of 9.3, this vulnerability poses a severe threat to the confidentiality and integrity of the organization's data.

Remediation

Immediate Action: Update the WooBeWoo Product Filter Pro plugin to the latest version immediately.

Proactive Monitoring: Monitor database query logs for unusual patterns or syntax that are characteristic of SQL injection attempts.

Compensating Controls: Utilize a Web Application Firewall (WAF) to filter and block malicious SQL injection payloads directed at the plugin.

Exploitation status

Public Exploit Available: No (exploit_available unknown)

Analyst recommendation

The high severity of this vulnerability necessitates prompt action. Administrators should ensure the plugin is updated to the latest version to prevent unauthorized database access and potential data breaches.