VYPR

WooCommerce Ajax Product Filter

by WCAPF

CVEs (1)

  • CVE-2026-3396HigApr 8, 2026
    risk 0.44cvss 7.5epss 0.01

    WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…