CVE-2026-66625: WordPress WC Vendors Marketplace plugin <= 2.7.2.1 - SQL Injection vulnerability
Published Sep 17, 2026
·Updated
Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
Affected Software
1 affected component
WordPress WC Vendors Marketplace plugin<=2.7.2.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WC Vendors Marketplace Pluginto a version that resolves this vulnerability.Fixed in 2.7.2.2
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs administrator-level privileges in the WordPress environment. The CVSS vector indicates exploitation is network-accessible, requires low attack complexity, and does not require user interaction.
2
What impact is indicated if exploitation succeeds?
The CVSS assessment indicates high confidentiality impact and low availability impact, with no integrity impact indicated. The score also indicates that the impact can extend beyond the vulnerable component's security scope.