OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96828

HIGH · CVSS 7.6 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

An SQL injection vulnerability exists in the Category Discount feature of WooCommerce versions up to 5.18, allowing attackers to manipulate database queries and potentially gain unauthorized access to sensitive data. This high-severity flaw could lead to data breaches or unauthorized actions within the application. E-commerce administrators using affected versions should prioritize patching this vulnerability to safeguard their systems against exploitation.

CVE
CVE-2026-96828
Severity
HIGH
CVSS
7.6
EPSS
0.28%

Original NVD Description

Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.