SQL Injection Vulnerability in YITH WooCommerce Membership Premium
CVE-2026-32552

8.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 August 2026

What is CVE-2026-32552?

A vulnerability affecting the YITH WooCommerce Membership Premium plugin allows unauthorized users to execute SQL Injection attacks on the database. This can lead to data breaches and unauthorized access. It is crucial for users of this plugin to update to the latest version to mitigate any potential security risks and protect sensitive information.

Affected Version(s)

YITH WooCommerce Membership Premium <= 2.33.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dutafi | Patchstack Bug Bounty Program
.