CVE-2026-32580: WordPress WooCommerce Lottery plugin <= 2.2.9 - SQL Injection vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.
Affected Software
1 affected component
WordPress WooCommerce Lottery<=2.2.9
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WordPress sites using the WooCommerce Lottery plugin version 2.2.9 or earlier are within the reported affected range.
2
Does exploitation require an attacker account or user interaction?
No. The vulnerability is described as unauthenticated, and the CVSS vector indicates no privileges or user interaction are required.
3
What impact is indicated by the severity vector?
The vector indicates high confidentiality impact and low availability impact, with no integrity impact. Exploitation is rated as high complexity and requires network access.