A critical unauthenticated SQL injection vulnerability has been identified in the WooBeWoo Product Filter Pro WordPress plugin affecting versions 3.1.8 and below. The vulnerability allows unauthenticated attackers to perform SQL injection attacks, potentially exposing sensitive database information. No authentication is required to exploit this flaw, significantly raising its risk level. The issue is tracked under CVE-2026-32554 and has been documented by both NVD and Patchstack. WooBeWoo Product Filter Pro is a WooCommerce-related plugin used for product filtering on WordPress e-commerce sites. Users are advised to update to a patched version immediately to mitigate exposure. The vulnerability was published via NVD and cross-referenced in the Patchstack vulnerability database.