CVE-2026-57777: WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection.
This issue affects WooCommerce: from n/a before 11.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Automattic WooCommerce (WordPress plugin)to a version that resolves this vulnerability.Fixed in 11.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs high privileges. Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.
What is the potential impact of successful exploitation?
The vulnerability allows blind SQL injection. The stated impact includes high confidentiality impact, no integrity impact, low availability impact, and a changed scope.
Which WooCommerce versions need to be remediated?
WooCommerce versions before 11.0 are affected. Upgrade to WooCommerce 11.0 or later.