VYPR
High severity7.6NVD Advisory· Published May 20, 2026· Updated May 20, 2026

CVE-2026-42383

CVE-2026-42383

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection.

This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.29.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Blind SQL injection in YITH WooCommerce Product Add-Ons plugin for WordPress allows attackers to extract database information.

Vulnerability

The YITH WooCommerce Product Add-Ons plugin for WordPress versions up to 4.29.0 fails to properly neutralize special elements used in SQL commands, leading to a blind SQL injection vulnerability. The issue exists in the plugin's handling of user-supplied input within product add-on fields. Affected versions: from n/a through 4.29.0 [1].

Exploitation

An attacker can exploit this vulnerability without authentication by sending crafted HTTP requests to the WordPress site, injecting malicious SQL queries. The blind nature means the attacker may not see direct output but can infer information based on response timing or error messages. The vulnerability is reportedly used in mass-exploit campaigns targeting thousands of websites [1].

Impact

Successful exploitation allows an attacker to interact with the underlying database, potentially extracting sensitive information such as user credentials, personal data, or other stored content. The CVSS score is 7.6 (High), indicating significant confidentiality impact [1].

Mitigation

The vulnerability is fixed in version 4.29.1. Users should update to this version immediately. If unable to update, consider contacting hosting provider or web developer for assistance. Patchstack users can enable auto-update for vulnerable plugins [1].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.