SQL Injection Vulnerability in Flycart UpsellWP Plugin
CVE-2026-32459
7.6HIGH
What is CVE-2026-32459?
An SQL injection vulnerability exists in the Flycart UpsellWP plugin, specifically allowing attackers to exploit improper neutralization of special elements used in SQL commands. This flaw facilitates blind SQL injection attacks, which could compromise the integrity of the database. It affects versions of UpsellWP up to and including 2.2.4, posing a risk to users who have not updated their installations.
Affected Version(s)
UpsellWP 0 <= 2.2.4