CVE-2026-82304 PUBLISHED

Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler

Assigner: WPScan
Reserved: 28.08.2026 Published: 05.09.2026 Updated: 05.09.2026

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

Product Status

Vendor Unknown
Product Music Store
Versions Default: unaffected
  • affected from 1.0.245 to 1.4.5 (excl.)

Credits

  • nobody finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE