SQL Injection Vulnerability in Lumise Product Designer for WooCommerce by WordPress
CVE-2026-9713
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 July 2026
What is CVE-2026-9713?
The Lumise Product Designer for WooCommerce plugin for WordPress has a vulnerability that allows for SQL Injection through improperly handled user inputs in the uploaded cart JSON file. Specifically, the 'id' and 'table' parameters used in the checkout AJAX action are not escaped correctly. This flaw enables unauthenticated attackers to manipulate existing SQL queries, potentially allowing them to extract sensitive information from the database. Versions up to and including 2.1.1 are susceptible to this serious security issue, making it essential for users to update their plugin to prevent exploitation.
Affected Version(s)
Product Designer for WooCommerce WordPress | Lumise 0 <= 2.1.1