Unauthenticated SQL Injection in eCommerce Product Catalog by WordPress
CVE-2026-52693

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-52693?

The eCommerce Product Catalog plugin for WordPress, versions 3.5.5 and below, is susceptible to an unauthenticated SQL Injection vulnerability. This flaw allows attackers to execute arbitrary SQL statements, potentially compromising the security of sensitive data within the database. Websites using this plugin without the latest updates are at risk of exploitation, disrupting functionality and exposing critical information.

Affected Version(s)

eCommerce Product Catalog <= 3.5.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aurélien BOURDOIS (Elymaro) | Patchstack Bug Bounty Program
.