Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-95601: Product Filter by WBW plugin can let attackers retrieve data
CVE-2026-95601 · published 5 days ago
Summary
The Product Filter by WBW plugin for WordPress, up to version 3.1.7, allows anyone on the internet to send specially crafted requests that can read data from your website’s database. This could expose private information or let attackers alter how your site works. Update the plugin to the latest version or remove it until it is fixed.
What to do
- Update wbw plugins product filter by wbw to version 3.1.8.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wbw plugins | product filter by wbw |
<= 3.1.7 Fix: upgrade to 3.1.8
|
Original advisory text
WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability
Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
Severity
9.3
Critical
CVSS 3.1: 9.3 (MITRE)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published23 Sep 2026
Updated27 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta