CVE-2026-102379: Villatheme Buildkit – Product Builder For Woocommerce – Custom Pc Builder
High severity, CVSS 8.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
Affected products
- Villatheme Buildkit – Product Builder For Woocommerce – Custom Pc Builder: up to and including 1.0.28
Published 2026-10-01. Last modified 2026-10-01.