CVE-2026-78472
Ni · WooCommerce Sales Report
The Ni WooCommerce Sales Report WordPress plugin contains a SQL injection vulnerability due to improper sanitization of user-supplied input, allowing unauthenticated attackers to access sensitive data.
Executive summary
A critical SQL injection vulnerability in the Ni WooCommerce Sales Report plugin allows unauthenticated attackers to extract database information, posing a significant risk to data confidentiality.
Vulnerability
The plugin fails to sanitize and escape input parameters before incorporating them into SQL statements. This flaw enables unauthenticated remote attackers to execute arbitrary SQL queries against the underlying database.
Business impact
Successful exploitation of this vulnerability permits unauthorized access to sensitive information stored within the WordPress database. Given the high CVSS score of 8.6, this flaw presents a severe risk of data breach, which could lead to regulatory non-compliance, loss of customer trust, and potential financial impact due to the exposure of private business or user data.
Remediation
Immediate Action: Update the Ni WooCommerce Sales Report plugin to version 4.2.0 or later immediately to resolve the vulnerable code path.
Proactive Monitoring: Review database query logs for suspicious patterns or anomalous SQL syntax that may indicate automated injection attempts targeting this plugin.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block common SQL injection patterns in incoming HTTP requests.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this SQL injection flaw cannot be overstated, as it grants unauthenticated attackers direct access to the application database. Administrators must prioritize updating the Ni WooCommerce Sales Report plugin to version 4.2.0 across all affected WordPress environments to eliminate this critical security risk.
More Ni CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.6 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Erwan LR (WPScan), with WPScan (coordinator), per the CVE Program record.