Junglewise Threat Intelligence

CVE-2026-3830: WBW Product Filter for WooCommerce SQL injection

CVE-2026-3830 · Severity: high · CVSS 8.6 · Published 2026-04-13

Executive brief

The Product Filter for WooCommerce by WBW, a WordPress plugin used to add advanced search and filtering to online stores, contains a security flaw that allows unauthenticated attackers to interact directly with the site's database. By sending a specially crafted request, an attacker could potentially steal sensitive information, including customer data or site configuration details. This could lead to a significant data breach and loss of customer trust.

Technical details

A SQL injection vulnerability exists in the Product Filter for WooCommerce by WBW plugin for WordPress due to insufficient sanitization and escaping of user-supplied parameters within the 'drawFilterAjax' and 'filtersFrontend' AJAX actions. Specifically, the 'f_list' parameter within the 'settings' array is vulnerable. An unauthenticated remote attacker can exploit this by sending a crafted POST request to 'wp-admin/admin-ajax.php', allowing them to execute arbitrary SQL commands. This can be used to extract sensitive data from the database via time-based or union-based techniques. The issue is fixed in version 3.1.3.

Affected products

  • WBW Product Filter for WooCommerce by WBW < 3.1.3

Timeline

  • 2026-03-23: disclosed: Publicly published on WPScan
  • 2026-03-23: patched: Fixed in version 3.1.3
  • 2026-04-13: advisory: NVD published date

References