CVE-2026-32552: WordPress YITH WooCommerce Membership Premium plugin <= 2.33.0 - SQL Injection vulnerability
Published Aug 19, 2026
·Updated
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
Affected Software
1 affected component
WordPress/YITH WooCommerce Membership Premium<=2.33.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress YITH WooCommerce Membership Premium pluginto a version that resolves this vulnerability.Fixed in 2.33.1
Event History
Aug 19, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is described as subscriber SQL injection, and the vector indicates low privileges are required. An attacker would need subscriber-level access to a vulnerable site; no user interaction is required.
2
Can this be exploited remotely?
Yes. The attack vector is network-based with low attack complexity, indicating exploitation can be performed remotely when the vulnerable functionality is reachable.
3
Which plugin versions are affected?
YITH WooCommerce Membership Premium versions 2.33.0 and earlier are affected by the available information.