Executive brief
A vulnerability exists in the Sender marketing automation plugin for WooCommerce, which is used by online stores to manage newsletters and email campaigns. An attacker with administrative access could execute unauthorized database commands, potentially leading to the theft of sensitive customer data or store information. While the attack requires high-level permissions, it could be used to escalate a minor breach into a full database compromise.
Technical details
The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress contains a SQL injection vulnerability (CWE-89) in versions up to and including 2.10.22. The flaw stems from improper neutralization of special elements used in SQL commands. An authenticated attacker with Administrator-level privileges can exploit this over the network to execute arbitrary SQL queries against the underlying database. This could result in unauthorized data retrieval or modification. The issue is addressed in version 2.10.23.
Affected products
- Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22
Timeline
- 2026-06-09: other: Reported by researcher
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: disclosed: CVE published to NVD
- 2026-07-27: patched: Fixed in version 2.10.23