SQL Injection Vulnerability in Riaxe Product Customizer Plugin for WordPress
CVE-2026-3599
7.5HIGH
What is CVE-2026-3599?
The Riaxe Product Customizer plugin for WordPress is susceptible to an SQL Injection vulnerability through the 'options' parameter keys in the 'product_data' of the /wp-json/InkXEProductDesignerLite/add-item-to-cart REST API endpoint. This issue arises from inadequate escaping of user-input parameters and insufficient preparation of the SQL queries in place. As a result, unauthenticated attackers can inject additional SQL commands into existing queries, potentially allowing for the retrieval of sensitive information from the database.
Affected Version(s)
Riaxe Product Customizer 0 <= 2.1.2