CVE-2026-3830: Unknown Product Filter For Woocommerce By Wbw
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
Affected products
- Unknown Product Filter For Woocommerce By Wbw: before 3.1.3 (fixed in 3.1.3)
Published 2026-04-13. Last modified 2026-06-17.