CVE-2026-74013: WordPress eShipper Commerce plugin <= 2.16.13 - SQL Injection vulnerability
Published Aug 20, 2026
·Updated
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Affected Software
1 affected component
WordPress eShipper Commerce plugin<=2.16.13
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires subscriber-level privileges. It can be exploited remotely without user interaction, and the attack complexity is low.
2
What is the potential impact if the vulnerability is exploited?
Successful exploitation can expose highly sensitive information and may cause a low availability impact. The scope is changed, meaning the vulnerable component can affect resources beyond its own authorization boundary.
3
Which plugin versions are affected?
eShipper Commerce versions up to and including 2.16.13 are affected.