CVE-2026-39494: Wbw Plugins Product Filter By Wbw
Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.
Affected products
- Wbw Plugins Product Filter By Wbw: up to and including 3.1.2
Published 2026-06-11. Last modified 2026-06-17.