Junglewise Threat Intelligence

CVE-2026-32551: DiviNext Woo Essential SQL injection

CVE-2026-32551 · Severity: critical · CVSS 9.3 · Published 2026-08-24

Executive brief

Woo Essential is a WordPress plugin used to enhance WooCommerce e-commerce functionality. A SQL injection vulnerability in versions up to 4.3.0 allows unauthenticated attackers to read, modify, or delete the entire website database, including customer accounts, order data, and payment information. This poses a critical risk to online stores and their customers.

Technical details

This is a SQL injection (SQLi) vulnerability in the Woo Essential WordPress plugin affecting versions through 4.3.0. The vulnerability stems from improper neutralization of special characters in SQL commands, allowing attackers to inject malicious SQL code. The attack requires no authentication and is exploitable remotely over the network. Successful exploitation allows an attacker to execute arbitrary SQL queries, enabling data exfiltration, modification, or deletion of the entire database. The vulnerability is patched in version 4.3.1 and later.

Affected products

  • DiviNext Woo Essential through 4.3.0

Timeline

  • 2026-08-24: disclosed: Published on NVD and Patchstack

References