CVE-2026-82304: Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler
Published Sep 5, 2026
·Updated
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Affected Software
1 affected component
WordPress plugin "Music Store" (eCommerce)<1.4.5
Event History
Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit it; no WordPress account or plugin-level authentication is required.
2
Which installations are affected?
Music Store WordPress plugin versions earlier than 1.4.5 are affected. The available information does not identify any configuration prerequisite.
3
What should be done if an immediate update is not possible?
The provided information does not document a workaround or mitigation. Prioritize updating the plugin to version 1.4.5 or later.