Executive brief
The Advance Product Search plugin for WooCommerce, which provides voice and instant search functionality for online stores, contains a security flaw. This vulnerability allows unauthorized individuals to bypass security controls and access sensitive information stored in the website's database. This could lead to the exposure of customer data or internal site configurations, potentially damaging the business's reputation and operational security.
Technical details
The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection due to insufficient escaping and lack of proper preparation on SQL queries within the 's' and 'match' parameters. The flaw exists in the thaps-function.php file. An unauthenticated attacker can exploit this by sending crafted web requests to append malicious SQL commands to existing queries. This enables the extraction of sensitive data from the WordPress database. The issue affects all versions up to and including 1.4.4; users should update to a patched version if available.
Affected products
- ThemeHunk Advance Product Search- Voice & Ajax Search for WooCommerce up to, and including, 1.4.4
Timeline
- 2026-07-16: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/th-advance-product-search/tags/1.4.4/inc/thaps-function.php
- https://plugins.trac.wordpress.org/browser/th-advance-product-search/tags/1.4.4/inc/thaps-function.php
- https://plugins.trac.wordpress.org/browser/th-advance-product-search/tags/1.4.4/inc/thaps-function.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3582785%40th-advance-product-search&new=3582785%40th-advance-product-search
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4aa8342f-1f36-4eb5-8b69-ab90fd85e5cb?source=cve