SQL Injection Vulnerability in GoPay for WooCommerce Plugin by WordPress
CVE-2026-75959
4.9MEDIUM
What is CVE-2026-75959?
The GoPay for WooCommerce plugin for WordPress is susceptible to an SQL Injection vulnerability that arises from inadequate escaping of user-supplied parameters in the 'log_table_filter' parameter. This flaw allows authenticated users with shop manager-level access and higher to inject additional SQL queries into existing ones, potentially leading to unauthorized access and extraction of sensitive information from the database. All versions up to and including 1.0.36 are affected, making it imperative for site administrators to apply the latest updates and security patches to mitigate risk.
Affected Version(s)
GoPay for WooCommerce 0 <= 1.0.36