CVE-2026-42714: WordPress Pix por Piggly (para Woocommerce) plugin <= 2.1.2 - SQL Injection vulnerability
Published Oct 7, 2026
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly (para Woocommerce): from n/a through 2.1.2.
Affected Software
1 affected component
Piggly Pix por Piggly (para WooCommerce)<=2.1.2
Event History
Oct 7, 2026
CVE Published
via MITRE·10:56 AM
Data Sourced
via MITRE·10:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Sites using Piggly Pix por Piggly (para WooCommerce) version 2.1.2 or earlier are affected. The available data does not identify a safe version.
2
What access does an attacker need to exploit it?
The attacker needs network access and high privileges. No user interaction is required.
3
What is the likely impact of successful exploitation?
The issue enables blind SQL injection and may expose confidential data. The supplied severity vector also indicates a low availability impact and no integrity impact.