← Terug naar overzicht

A critical SQL Injection vulnerability (CVE-2026-57777) has been identified in Automattic's WooCommerce plugin, classified as Blind SQL Injection. The vulnerability stems from improper neutralization of special elements used in SQL commands. All WooCommerce versions prior to 11.0 are affected. The flaw allows attackers to perform blind SQL injection attacks, potentially exposing sensitive database contents without direct error feedback. A patch has been made available via a pull request on the WooCommerce GitHub repository. The vulnerability has been documented by both NVD/NIST and Patchstack security databases. Users are strongly advised to update to WooCommerce version 11.0 or later to remediate the issue. The vulnerability carries a high criticality rating given the potential for unauthorized database access and data exfiltration.

Affected products

  • WooCommerce (versions before 11.0)
  • WordPress WooCommerce Plugin

Related CVE's

  • CVE-2026-57777

Categories

  • Database & Storage
  • Enterprise Applications
  • Web Technologies