← Terug naar overzicht

A critical SQL Injection vulnerability (CVE-2026-57777) has been identified in Automattic's WooCommerce plugin, classified as Blind SQL Injection. The vulnerability stems from improper neutralization of special elements used in SQL commands. All versions of WooCommerce prior to 11.0 are affected. The issue has been patched in version 11.0, with a corresponding pull request available on GitHub. The vulnerability was also documented by Patchstack, referencing it in context of WooCommerce plugin version 10.9.4. Blind SQL Injection can allow attackers to extract sensitive database information without direct error feedback, posing significant risk to WordPress-based e-commerce sites. Site administrators are strongly advised to update to WooCommerce 11.0 or later immediately to mitigate the risk.

Affected products

  • WooCommerce (versions before 11.0)

Related CVE's

  • CVE-2026-57777

Categories

  • Database & Storage
  • Enterprise Applications
  • Web Technologies