CVE-2026-95601: WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
Affected Software
1 affected component
WBW Product Filter by WBW<=3.1.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Product Filter by WBWto a version that resolves this vulnerability.Fixed in 3.1.8
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be treated as exposed?
WordPress sites running Product Filter by WBW version 3.1.7 or earlier should be treated as affected.
2
Does exploitation require an authenticated WordPress account or user interaction?
No. The vulnerability is unauthenticated and has a network attack vector; no user interaction is required.
3
How can I determine whether my site is affected?
Check the installed version of the Product Filter by WBW plugin. Versions 3.1.7 and earlier are affected according to the available data.