Time-Based SQL Injection in WooCommerce Lottery Plugin by WordPress
CVE-2026-18884

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 August 2026

What is CVE-2026-18884?

The WooCommerce Lottery plugin for WordPress is susceptible to a Time-Based SQL Injection originating from the 'orderby' and 'order' GET parameters. This vulnerability arises due to inadequate escaping of user-supplied input and deficiencies in the preparation of the SQL query used by the plugin. As a result, unauthenticated attackers can inject additional SQL queries into existing ones, potentially exposing sensitive data from the database. This puts users at risk, highlighting the need for immediate updates and patching to secure their systems.

Affected Version(s)

WooCommerce Lottery 0 <= 2.2.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

h0xilo
.