CVE-2026-81277: WordPress Suggestion Engine for WooCommerce plugin <= 2.0.11 - SQL Injection vulnerability
Published Aug 27, 2026
·Updated
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Affected Software
1 affected component
WordPress/WooCommerce Suggestion Engine<=2.0.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Suggestion Engine for WooCommerce Pluginto a version that resolves this vulnerability.Fixed in 2.0.12
Event History
Aug 27, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is exploitable by an attacker with Contributor-level access. User interaction is not required.
2
Can this be exploited remotely?
Yes. The CVSS vector identifies network access as the attack vector and low attack complexity.
3
Which versions are affected?
Suggestion Engine for WooCommerce versions 2.0.11 and earlier are affected.