CVE-2026-42383: WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection.
This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.29.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress YITH WooCommerce Product Add-Ons Pluginto a version that resolves this vulnerability.Fixed in 4.29.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42383?
CVE-2026-42383 has a high severity rating due to the potential for SQL Injection attacks that can compromise sensitive database information.
How do I fix CVE-2026-42383?
To resolve CVE-2026-42383, update the YITH WooCommerce Product Add-Ons plugin to a version higher than 4.29.0.
Which versions of YITH WooCommerce Product Add-Ons are affected by CVE-2026-42383?
CVE-2026-42383 affects all versions of YITH WooCommerce Product Add-Ons up to and including version 4.29.0.
What type of vulnerability is CVE-2026-42383?
CVE-2026-42383 is classified as an SQL Injection vulnerability, allowing attackers to execute unauthorized SQL commands.
What impact does CVE-2026-42383 have on WordPress installations?
The impact of CVE-2026-42383 includes potential data theft and manipulation through unauthorized database access via SQL Injection.