Executive brief
WooCommerce Frontend Manager – Ultimate is a WordPress plugin that provides an advanced dashboard for managing e-commerce stores. A security flaw allows logged-in users with basic 'Subscriber' permissions to execute unauthorized database commands. This could lead to the theft of sensitive customer data, site configuration details, or other information stored in the website's database.
Technical details
A SQL injection vulnerability exists in the WooCommerce Frontend Manager – Ultimate plugin for WordPress in versions prior to 6.7.7. The flaw is caused by improper neutralization of user-supplied input in a component accessible to authenticated users. An attacker with 'Subscriber' level privileges can send specially crafted requests to the server to execute arbitrary SQL commands. This can be leveraged to bypass security controls and extract sensitive data from the WordPress database. The issue is resolved in version 6.7.7.
Affected products
- WC Lovers WooCommerce Frontend Manager – Ultimate < 6.7.7
Timeline
- 2025-10-09: other: Vulnerability reported by researcher 0xd4rk5id3
- 2026-01-15: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: CVE published and NVD record created
- 2026-06-17: patched: Patch confirmed available in version 6.7.7