Executive brief
YITH WooCommerce Product Add-Ons is a WordPress plugin used to add custom options and features to products in an online store. A security flaw in this plugin could allow an attacker with administrative or shop manager access to interact directly with the website's database. This could lead to the unauthorized extraction of sensitive customer data or internal site information.
Technical details
A Blind SQL Injection vulnerability exists in the YITH WooCommerce Product Add-Ons plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw is present in versions up to and including 4.29.0. An attacker with high-level privileges, such as a Shop Manager or Administrator, can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries against the backend database, potentially leading to full data exfiltration. The issue has been addressed in version 4.29.1.
Affected products
- YITH YITH WooCommerce Product Add-Ons up to 4.29.0
Timeline
- 2026-01-26: other: Reported by Nguyen Ba Khanh
- 2026-05-20: advisory: Published by Patchstack
- 2026-05-20: patched: Version 4.29.1 released