CVE-2026-32551 describes an unauthenticated SQL injection vulnerability affecting the Woo Essential WordPress plugin in versions 4.3.0 and below. The vulnerability allows unauthenticated attackers to interact directly with the database, potentially enabling data extraction, modification, or deletion. No authentication is required to exploit this flaw, making it particularly dangerous for any WordPress site running the affected plugin. The issue has been documented on both the NVD and Patchstack databases. Users are advised to update the plugin beyond version 4.3.0 to remediate the vulnerability. The criticality is rated High due to the unauthenticated nature of the exploit and the potential for significant data compromise.