Junglewise Threat Intelligence

CVE-2026-52693: eCommerce Product Catalog SQL injection

CVE-2026-52693 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Executive brief

The eCommerce Product Catalog plugin for WordPress, which is used to manage and display product listings on websites, contains a critical security flaw. An unauthorized attacker can use this vulnerability to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information, site data, or disruption of the online store's operations.

Technical details

A SQL injection vulnerability exists in the eCommerce Product Catalog plugin for WordPress (versions <= 3.5.5) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers via the network, requiring no user interaction. By sending specially crafted requests, an attacker can bypass authentication and directly query the underlying database. This can result in high confidentiality impact through data exfiltration and low availability impact. The issue is resolved in version 3.5.6.

Affected products

  • impleCode eCommerce Product Catalog <= 3.5.5

Timeline

  • 2026-05-23: other: Reported by Aurélien BOURDOIS (Elymaro)
  • 2026-06-09: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-06-09: patched: Version 3.5.6 released to address the vulnerability

References

Related threats