Junglewise Threat Intelligence

CVE-2026-32550: Kadence Shop Kit SQL injection in subscriber function

CVE-2026-32550 · Severity: high · CVSS 8.5 · Published 2026-08-27

Executive brief

Kadence Shop Kit is a WordPress plugin that enables e-commerce functionality on WordPress sites. A SQL injection vulnerability in versions 3.0.6 and earlier allows authenticated subscribers to execute arbitrary database queries, potentially exposing, modifying, or deleting sensitive customer data, user accounts, and private business information.

Technical details

A SQL injection vulnerability exists in the Kadence Shop Kit WordPress plugin (versions ≤ 3.0.6) that requires subscriber-level authentication to exploit. The vulnerability allows an authenticated attacker with subscriber privileges to inject malicious SQL code through an unspecified parameter or function, enabling arbitrary database queries. An attacker can read, modify, or delete the entire database including user credentials and private customer data. The patch is available in version 3.0.6.1 and later. This is classified as OWASP A3: Injection (SQL Injection).

Affected products

  • Kadence Shop Kit ≤ 3.0.6

Timeline

  • 2026-08-27: disclosed: Published on NVD and Patchstack
  • 2026-08-25: patched: Patched in version 3.0.6.1
  • 2026-07-27: advisory: Initially reported by dutafi

References