CVE-2026-32551: WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Affected Software
1 affected component
wordpress-plugins/woo-essential<=4.3.0
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
2
Which installations are affected?
Woo Essential versions 4.3.0 and earlier are identified as affected. The provided data does not state whether any particular plugin configuration is required.
3
What is the potential impact?
The supplied severity vector indicates network-reachable exploitation with low attack complexity, high confidentiality impact, and low availability impact. It does not identify a specific data set that could be exposed or the exact availability effect.