Unauthenticated SQL Injection in WooCommerce Active Products Tables
CVE-2026-66436

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-66436?

An unauthenticated SQL Injection vulnerability exists in the Active Products Tables for WooCommerce plugin, allowing attackers to manipulate database queries without authentication. This security flaw affects versions up to 1.1.1, posing a risk of unauthorized access to sensitive data. Attackers could exploit this weakness to execute arbitrary SQL commands, potentially leading to data leakage or unauthorized alterations within the WooCommerce system.

Affected Version(s)

Active Products Tables for WooCommerce <= 1.1.1

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Asim Alshaya | Patchstack Bug Bounty Program
.