CVE-2026-32554: WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Affected Software
1 affected component
wordpress/WooBeWoo Product Filter Pro<=3.1.8
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation over the network.
2
Which plugin versions are affected?
WooBeWoo Product Filter Pro versions 3.1.8 and earlier are identified as affected.
3
Does exploitation require user interaction or special conditions?
The supplied severity vector indicates low attack complexity and no user interaction requirement. It is remotely reachable over the network.
4
What impact could successful exploitation have?
The severity vector indicates high confidentiality impact and low availability impact, with no integrity impact specified. The scope is marked as changed.