CVE-2026-96828: WordPress Category Discount Woocommerce plugin <= 5.18 - SQL Injection vulnerability
Published Sep 30, 2026
·Updated
Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
Affected Software
1 affected component
WordPress Category Discount Woocommerce<=5.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Category Discount Woocommerce Pluginto a version that resolves this vulnerability.Fixed in 5.19
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as an administrator SQL injection, and the vector requires high privileges. An attacker would need administrator-level access to the affected WordPress site.
2
Which plugin versions are affected?
Category Discount Woocommerce versions 5.18 and earlier are affected.
3
Is the vulnerability remotely exploitable without authentication?
No. Although the attack vector is network-based and requires no user interaction, exploitation requires high privileges, so it is not an unauthenticated attack.