VYPR
High severity7.2NVD Advisory· Published Mar 13, 2026· Updated Apr 22, 2026

CVE-2026-32414

CVE-2026-32414

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion.This issue affects Advanced Woo Labels: from n/a through <= 2.36.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A code injection vulnerability in Advanced Woo Labels plugin (≤2.36) allows unauthenticated remote code execution via code injection.

Vulnerability

Overview The Advanced Woo Labels plugin for WordPress, versions up to and including 2.36, contains a code injection vulnerability (CWE-94) that allows remote code execution. The issue stems from improper control over the generation of code, enabling an attacker to inject and execute arbitrary PHP code on the target server [1].

Exploitation

Details This vulnerability can be exploited remotely without authentication, making it particularly dangerous. Attackers can send specially crafted requests to inject malicious code, which is then executed by the server. The attack surface is the plugin's code generation functionality. No special privileges or user interaction are required [1].

Impact

Successful exploitation grants the attacker the ability to execute arbitrary commands on the affected WordPress site. This can lead to complete site compromise, including backdoor installation, data theft, and full control over the website. The vulnerability is known to be used in mass-exploit campaigns targeting thousands of websites regardless of size or popularity [1].

Mitigation

The vendor has released a patched version; users must update Advanced Woo Labels to version 2.37 or later immediately. If updating is not possible, it is recommended to contact the hosting provider or a web developer for assistance. No workaround is available [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.