Time-Based SQL Injection in WooCommerce Lottery Plugin by WordPress
CVE-2026-18884
7.5HIGH
What is CVE-2026-18884?
The WooCommerce Lottery plugin for WordPress is susceptible to a Time-Based SQL Injection originating from the 'orderby' and 'order' GET parameters. This vulnerability arises due to inadequate escaping of user-supplied input and deficiencies in the preparation of the SQL query used by the plugin. As a result, unauthenticated attackers can inject additional SQL queries into existing ones, potentially exposing sensitive data from the database. This puts users at risk, highlighting the need for immediate updates and patching to secure their systems.
Affected Version(s)
WooCommerce Lottery 0 <= 2.2.9