Junglewise Threat Intelligence

CVE-2026-52700: WCMultiShipping SQL injection in WordPress plugin

CVE-2026-52700 · Severity: high · CVSS 8.5 · Published 2026-06-15

Executive brief

WCMultiShipping is a WordPress plugin used to manage complex shipping logistics for e-commerce stores. A security flaw allows logged-in users with basic 'Subscriber' permissions to execute unauthorized database commands. This could lead to the theft of sensitive customer data, exposure of site configuration details, or disruption of store operations.

Technical details

A SQL injection vulnerability (CWE-89) exists in the WCMultiShipping plugin for WordPress in versions up to and including 3.0.2. The flaw stems from improper neutralization of special elements used in SQL commands, allowing an authenticated attacker with Subscriber-level privileges to perform unauthorized database queries. By sending crafted requests, an attacker can extract sensitive information from the database or potentially impact site availability. The vulnerability is reachable over the network without user interaction. A fix is available in version 3.0.3.

Affected products

  • WCMultiShipping WCMultiShipping <= 3.0.2

Timeline

  • 2026-05-10: other: Reported by researcher ParkHyunWoo
  • 2026-06-10: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References