Unauthenticated SQL Injection Vulnerability in Woo Essential Plugin by WooCommerce
CVE-2026-32551
9.3CRITICAL
What is CVE-2026-32551?
A vulnerability has been identified in the Woo Essential plugin for WooCommerce, which is susceptible to unauthenticated SQL injection. This issue affects versions up to 4.3.0. An attacker exploiting this vulnerability could execute arbitrary SQL statements on the database, potentially compromising sensitive data and the integrity of the application. Organizations using this plugin should take immediate action to secure their installations by upgrading to the latest version and implementing best security practices.
Affected Version(s)
Woo Essential <= 4.3.0