VYPR

Lumise Product Designer for WooCommerce

by WordPress

CVEs (1)

  • CVE-2026-9713Jul 23, 2026
    risk 0.00cvss epss 0.00

    The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping…