All verified exploits

CVE-2026-2579 Unauthenticated SQL Injection via Product Search

Deterministic high WordPress Added cve-verified-cve-2026-2579

Detects WordPress installs running the WowStore (product-blocks) plugin at version 4.4.3 or earlier. The plugin's product-search REST endpoint accepts unauthenticated POST requests and interpolates the search parameter directly into SQL LIKE clauses without $wpdb->prepare(). An attacker can inject SQL to extract user credentials, customer orders, and any other data from the WordPress database. Affects WowStore versions up to and including 4.4.3.

Related WordPress exploits

Is your app exploitable through CVE-2026-2579?

Scan your domain free