CVE-2026-73345: WordPress License Manager for WooCommerce plugin <= 3.0.18 - SQL Injection vulnerability
Published Aug 18, 2026
·Updated
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
Affected Software
1 affected component
WordPress License Manager for WooCommerce<=3.0.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress License Manager for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 3.0.19
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation requires network access, low privileges, and high attack complexity. No user interaction is required.
2
Which versions are affected, and is a fix identified?
The affected versions are License Manager for WooCommerce 3.0.18 and earlier. The available data does not identify a fixed version or a workaround.
3
Which deployments should be prioritized for investigation?
The vulnerability is described as a customer SQL injection, so deployments where customer-facing functionality is exposed are relevant to triage. The provided information does not specify the affected endpoint or request parameter.