SQL Injection Vulnerability in WCMultiShipping Plugin for WordPress
CVE-2026-52700
8.5HIGH
What is CVE-2026-52700?
The WCMultiShipping plugin for WordPress, up to version 3.0.2, is susceptible to SQL injection attacks. This vulnerability could allow an attacker to manipulate database queries by injecting malicious SQL statements. Successful exploitation can lead to unauthorized data access or modification, posing a significant risk to the integrity and confidentiality of user data. It is vital for users of the affected versions to apply updates promptly and secure their installations against potential exploitation.
Affected Version(s)
WCMultiShipping <= 3.0.2