Executive brief
WooBeWoo Product Filter Pro is a WordPress plugin that enables product filtering on e-commerce sites. An unauthenticated SQL injection vulnerability allows attackers to read, modify, or delete the entire database including customer accounts and private data without any credentials. Affected sites running version 3.1.8 and earlier are at critical risk of mass-exploitation campaigns.
Technical details
The vulnerability is a SQL injection flaw in WooBeWoo Product Filter Pro version 3.1.8 and earlier that does not require authentication to exploit. The plugin fails to properly sanitize user input in database queries, allowing an attacker on the network to inject malicious SQL commands. This can result in full database read, write, and delete access, compromising customer data, user credentials, and all stored information. No official patch is currently available; immediate mitigation via security plugins or removal is recommended.
Affected products
- WooBeWoo Product Filter Pro ≤ 3.1.8
Timeline
- 2026-08-24: disclosed
- 2026-07-03: other: Reported by Luis Koleski