CVE 9.3 CRITICAL

WordPress Product Filter by WBW plugin <= 3.1.2 - SQL Injection vulnerability_CVE-2026-39494

9.3 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection.

This issue affects Product Filter by WBW: from n/a through 3.1.2.

AI Analysis

SQL Injection vulnerability in Product Filter by WBW plugin

Basic Information

ID CVE-2026-39494
Source Patchstack
Published Jun 11, 2026 at 21:05

Affected Product

Vendor WBW Plugins
Product Product Filter by WBW
Version n/a
Affected Versions WBW Plugins Product Filter by WBW n/a

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor WBW Plugins
Product Product Filter by WBW
Version <= 3.1.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.