Junglewise Threat Intelligence

CVE-2026-75959: GoPay for WooCommerce SQL injection in log table filter

CVE-2026-75959 · Severity: medium · CVSS 4.9 · Published 2026-09-19

Executive brief

The GoPay for WooCommerce plugin, which handles payment processing for online shops, contains a SQL injection vulnerability in its logging feature. Attackers with shop manager privileges or higher can inject malicious SQL queries to extract sensitive data from the store's database, such as customer information or transaction records.

Technical details

The vulnerability exists in the 'log_table_filter' parameter, which lacks proper escaping and prepared statement usage, allowing authenticated attackers with shop manager-level access to inject arbitrary SQL commands. The flaw is present in all versions up to and including 1.0.36 in the plugin's logging functionality. An attacker with the required permissions can extract sensitive information from the WordPress database.

Affected products

  • GoPay GoPay for WooCommerce up to and including 1.0.36

Timeline

  • 2026-09-19: disclosed

References