SQL Injection Vulnerability in Lumise Product Designer for WooCommerce by WordPress
CVE-2026-9713

7.5HIGH

What is CVE-2026-9713?

The Lumise Product Designer for WooCommerce plugin for WordPress has a vulnerability that allows for SQL Injection through improperly handled user inputs in the uploaded cart JSON file. Specifically, the 'id' and 'table' parameters used in the checkout AJAX action are not escaped correctly. This flaw enables unauthenticated attackers to manipulate existing SQL queries, potentially allowing them to extract sensitive information from the database. Versions up to and including 2.1.1 are susceptible to this serious security issue, making it essential for users to update their plugin to prevent exploitation.

Affected Version(s)

Product Designer for WooCommerce WordPress | Lumise 0 <= 2.1.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bashu
.