Unauthenticated SQL Injection in Product Filter by WBW
CVE-2026-95601
9.3CRITICAL
What is CVE-2026-95601?
The Product Filter by WBW plugin for WordPress contains a vulnerability that allows unauthenticated users to execute SQL injection attacks. This flaw is present in versions 3.1.7 and below, potentially enabling attackers to manipulate the database queries, which may lead to unauthorized data exposure or other harmful actions. Website administrators should promptly update to secure versions to mitigate these risks.
Affected Version(s)
Product Filter by WBW <= 3.1.7