OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-32580

HIGH · CVSS 7.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An unauthenticated SQL injection vulnerability exists in WooCommerce Lottery versions up to 2.2.9, allowing attackers to execute arbitrary SQL queries on the database. This can lead to unauthorized data access, data manipulation, or even complete system compromise. E-commerce platforms using affected versions should prioritize patching this vulnerability to safeguard sensitive customer and transaction data.

CVE
CVE-2026-32580
Severity
HIGH
CVSS
7.5
EPSS
0.31%

Original NVD Description

Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.