SQL Injection Vulnerability in WBW Plugins Product Filter
CVE-2026-39494

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 June 2026

What is CVE-2026-39494?

The WBW Plugins Product Filter is susceptible to an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands through improper neutralization of special elements in SQL queries. This flaw affects all versions of the product up to and including 3.1.2, enabling potential data leaks or manipulation. It is crucial for users to patch their installations to maintain the integrity of their databases and safeguard against unauthorized access.

Affected Version(s)

Product Filter by WBW <= 3.1.2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.