Junglewise Threat Intelligence

CVE-2016-20065: EvWill Product Catalog 8 SQL injection in UpdateCategoryList

CVE-2016-20065 · Severity: high · CVSS 8.2 · Published 2026-06-09

Executive brief

The Product Catalog 8 plugin for WordPress, used to display product listings, contains a security flaw that allows unauthorized individuals to access your website's database. By sending a specially crafted request, an attacker can steal sensitive information such as user credentials or site configuration data. This plugin was discontinued in 2014 and is no longer receiving security updates, posing a significant risk to any sites still using it.

Technical details

An SQL injection vulnerability exists in the Product Catalog 8 plugin (version 1.2.0) for WordPress due to insufficient sanitization of the 'selectedCategory' POST parameter. The vulnerable function, UpdateCategoryList(), is accessible to unauthenticated users via the WordPress AJAX handler (admin-ajax.php). An attacker can exploit this by sending a crafted POST request containing UNION-based SQL queries to extract sensitive data from the WordPress database, including user hashes and configuration details. The plugin has been closed on the WordPress repository since 2014, and no official patch is available; users are advised to uninstall the software.

Affected products

  • EvWill Product Catalog 8 1.2.0

Timeline

  • 2014-09-15: other: Plugin closed on WordPress.org repository
  • 2016-11-12: disclosed: Vulnerability discovered and exploit published on Exploit-DB
  • 2026-06-09: advisory: CVE-2016-20065 published by NVD/VulnCheck

References