Executive brief
Beautiful Taxonomy Filters is a WordPress plugin that allows site managers to organize and display product categories and tags. An unauthenticated attacker can exploit a SQL injection vulnerability to read, modify, or delete the entire database, including user credentials and private customer data, potentially compromising the entire website.
Technical details
Beautiful Taxonomy Filters plugin versions 2.4.6 and earlier contain an unauthenticated SQL injection vulnerability in the plugin's taxonomy filtering logic. The vulnerability arises from improper sanitization and parameterization of user-supplied input in database queries. An attacker can craft malicious requests that inject arbitrary SQL commands without requiring authentication or user interaction. Successful exploitation allows complete database compromise, including reading sensitive data, modifying records, or deleting content. The vulnerability has been patched in version 2.4.7 and later; immediate updates are strongly recommended.
Affected products
- Beautiful Taxonomy Filters Beautiful Taxonomy Filters <=2.4.6
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Version 2.4.7 or later