Junglewise Threat Intelligence

CVE-2026-39441: Naked Cat Plugins Feed KuantoKusta for WooCommerce SQL injection

CVE-2026-39441 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Executive brief

A security vulnerability exists in the Feed KuantoKusta for WooCommerce plugin, which is used by online stores to sync product data with the KuantoKusta marketplace. An attacker can exploit this flaw to gain unauthorized access to the website's database without needing a password. This could lead to the theft of sensitive customer information, site data, or a partial disruption of online store operations.

Technical details

The Feed KuantoKusta for WooCommerce – Free plugin for WordPress is vulnerable to an unauthenticated SQL injection due to improper neutralization of special elements used in an SQL command (CWE-89). The vulnerability exists in versions up to and including 5.3. Because the flaw is reachable by unauthenticated users over the network, a remote attacker can send specially crafted requests to execute arbitrary SQL queries against the backend database. This can result in the extraction of sensitive data or unauthorized modification of database records. The issue has been addressed in version 5.3.1.

Affected products

  • Naked Cat Plugins (by Webdados) Feed KuantoKusta for WooCommerce – Free <= 5.3

Timeline

  • 2026-04-04: other: Reported by TruongLV1 From FPT Night Wolf
  • 2026-04-22: disclosed: Vulnerability published by Patchstack
  • 2026-04-22: patched: Patch released in version 5.3.1
  • 2026-06-15: advisory: CVE published in NVD

References