Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-95601: Product Filter by WBW plugin can let attackers retrieve data

CVE-2026-95601 · published 5 days ago
Summary

The Product Filter by WBW plugin for WordPress, up to version 3.1.7, allows anyone on the internet to send specially crafted requests that can read data from your website’s database. This could expose private information or let attackers alter how your site works. Update the plugin to the latest version or remove it until it is fixed.

What to do
  • Update wbw plugins product filter by wbw to version 3.1.8.
Affected software
VendorProductAffected versions
wbw plugins product filter by wbw <= 3.1.7
Fix: upgrade to 3.1.8
Original advisory text
WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability
Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
Severity
9.3 Critical
CVSS 3.1: 9.3 (MITRE)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published23 Sep 2026
Updated27 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-95601 · MITRE
Track software like this
Free during beta