SQL Injection Vulnerability in WooCommerce by Automattic
CVE-2026-57777
7.6HIGH
What is CVE-2026-57777?
An SQL injection vulnerability in the WooCommerce plugin developed by Automattic allows for improper handling of special elements within SQL commands, leading to a potential blind SQL injection attack. This vulnerability affects all WooCommerce versions prior to 11.0, making it crucial for users to update immediately to safeguard against unauthorized data access and manipulation.
Affected Version(s)
WooCommerce < 11.0