CVE-2026-87770 PUBLISHED

Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product

Assigner: WPScan
Reserved: 09.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

Product Status

Vendor Unknown
Product Price Drop Alert for Woo Commerce
Versions Default: unknown
  • affected from 0 to 1.1 (incl.)

Credits

  • Theo Antônio Da Fonseca finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE