CVE-2026-66631: WordPress MC Woocommerce Wishlist plugin <= 1.9.21 - SQL Injection vulnerability
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MC Woocommerce Wishlist Pluginto a version that resolves this vulnerability.Fixed in 2.0.0
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker needs high privileges, consistent with WordPress administrator-level access. The issue is remotely reachable over the network and does not require user interaction.
What is the likely impact of successful exploitation?
Successful exploitation may expose highly sensitive information through SQL injection. The available severity vector indicates no direct integrity impact and a low availability impact, while the impact may extend beyond the vulnerable component.
Which deployments should be prioritized for review?
Prioritize WordPress sites using MC Woocommerce Wishlist version 1.9.21 or earlier, especially where administrator accounts are shared, insufficiently protected, or potentially compromised.