Executive brief
A vulnerability exists in the Product Filter by WBW plugin, which is used by WordPress websites to provide advanced product searching and filtering for e-commerce. An attacker can exploit this flaw to gain unauthorized access to the website's database, potentially stealing sensitive customer information or administrative data. This could lead to a significant data breach and loss of customer trust.
Technical details
The Product Filter by WBW plugin for WordPress contains a Blind SQL Injection vulnerability due to improper neutralization of special elements in SQL commands (CWE-89). The flaw allows an unauthenticated remote attacker to send specially crafted requests to the web server to execute arbitrary SQL queries against the backend database. Because the vulnerability is 'blind,' the attacker can infer data by observing differences in server responses or timing. This can lead to full database extraction, including sensitive user credentials and site configuration. The issue is resolved in version 3.1.3.
Affected products
- WBW Plugins Product Filter by WBW <= 3.1.2
Timeline
- 2026-02-19: other: Reported by researcher daroo
- 2026-04-13: advisory: Initial advisory published by Patchstack
- 2026-06-11: disclosed: CVE published to NVD dataset
- 2026-04-13: patched: Version 3.1.3 released to address the vulnerability