VYPR

Woocommerce Lottery

by WordPress

CVEs (1)

  • CVE-2026-18884HigAug 26, 2026
    risk 0.49cvss 7.5epss

    The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…