CVE-2026-32554
9.3WBW · WooBeWoo Product Filter Pro
An unauthenticated SQL injection vulnerability in the WooBeWoo Product Filter Pro plugin up to version 3.1.8 allows attackers to execute arbitrary database queries.
Executive summary
The WBW WooBeWoo Product Filter Pro plugin contains a critical SQL injection vulnerability that allows unauthenticated attackers to compromise database integrity.
Vulnerability
This is an SQL injection vulnerability (CWE-89) affecting the plugin, which fails to properly sanitize user-supplied input before processing database queries. The vulnerability is exploitable by unauthenticated remote attackers.
Business impact
Successful exploitation allows an attacker to interact directly with the underlying database, potentially leading to unauthorized data disclosure, modification, or deletion. With a CVSS score of 9.3, this vulnerability poses a severe threat to the confidentiality and integrity of the organization's data.
Remediation
Immediate Action: Update the WooBeWoo Product Filter Pro plugin to the latest version immediately.
Proactive Monitoring: Monitor database query logs for unusual patterns or syntax that are characteristic of SQL injection attempts.
Compensating Controls: Utilize a Web Application Firewall (WAF) to filter and block malicious SQL injection payloads directed at the plugin.
Exploitation status
Public Exploit Available: No (exploit_available unknown)
Analyst recommendation
The high severity of this vulnerability necessitates prompt action. Administrators should ensure the plugin is updated to the latest version to prevent unauthorized database access and potential data breaches.