CVE-2026-32551 describes an unauthenticated SQL injection vulnerability affecting the Woo Essential WordPress plugin in versions 4.3.0 and below. The vulnerability allows unauthenticated attackers to inject malicious SQL queries, potentially leading to unauthorized database access, data exfiltration, or data manipulation. No authentication is required to exploit this flaw, significantly raising its risk level. The issue has been documented by both the NVD and Patchstack. Users of the affected plugin are advised to update to a patched version immediately. The vulnerability is categorized as high severity due to its unauthenticated nature and potential for full database compromise.