CVE-2026-39494
critical · 9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.
9.3
CVSS
0.4%
EPSS (exploit prob.)
33rd
EPSS percentile
2026-06-11
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Weaknesses
CWE-89
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-39494