AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-66436

CRITICAL · CVSS 9.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

An unauthenticated SQL injection vulnerability exists in the Active Products Tables of WooCommerce versions up to 1.1.1, allowing attackers to execute arbitrary SQL queries. This critical flaw can lead to unauthorized data access and manipulation, potentially compromising sensitive customer information and site integrity. E-commerce platforms using affected WooCommerce versions should prioritize immediate patching to mitigate risks associated with this vulnerability.

CVE
CVE-2026-66436
Severity
CRITICAL
CVSS
9.3
EPSS
0.29%

Original NVD Description

Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.