External risk intelligence

Unauthenticated SQL Injection in Product Filter by WBW

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-95601

This vulnerability affects a WordPress product filter plugin. Such plugins are designed to be used on the public-facing front end of websites to allow users to interact with and filter product catalogs, making the vulnerable component commonly exposed to the public internet.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a product filter technology that allows unauthenticated access, meaning an attacker could exploit it without needing a login. This issue could potentially impact the integrity and availability of data within affected systems. The main concern is confirming if this specific technology is in use and, if so, understanding the extent of potential exposure.

  • Unauthenticated flaw in product filter technology.
  • Important for understanding potential data exposure.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can target a website using a vulnerable product filter plugin. Since the vulnerability is unauthenticated, an attacker does not need any special access to the website to initiate the attack. By sending specially crafted requests to the product filter feature, an attacker can trigger the SQL injection, potentially allowing them to access or manipulate sensitive database information.

  • No authentication required.
  • SQL injection via product filter.
  • Access sensitive database information.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated SQL injection vulnerability in a product filter plugin could allow an attacker to interfere with service operations or access sensitive information when supported by the advisory.

  • System data could be compromised.
  • Via network requests.
  • Service may become unavailable.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated SQL injection in the Product Filter impacts external-facing web applications, suggesting responsibility likely lies with web application owners, platform teams managing the WordPress environment, and potentially network/security teams overseeing exposure. The first practical step is to identify all instances of the affected plugin, confirm public accessibility and business criticality, and then coordinate with the accountable owner for remediation.

  • Application and platform owners should address.
  • Verify public exposure and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Product Filter by WBW?

Product Filter by WBW is a WordPress plugin used to add search and sorting capabilities to online store catalogs. It helps website visitors narrow down products by attributes like category, price, or size, enhancing the user experience on e-commerce sites.

How does CVE-2026-95601 function as a SQL injection?

This vulnerability, classified as CWE-89, happens when the plugin fails to sanitize user-provided input before using it in database queries. Because the software does not properly block malicious code, an attacker can input database commands through the filter feature to view or potentially alter information stored in the system's database.

Do I need to be logged in for this to be triggered?

No, authentication is not required to trigger this vulnerability. The flaw exists in the public-facing component of the plugin, meaning an attacker can initiate a request from the internet without needing a user account or administrative privileges to interact with the database.

Why is this CVE considered internet-facing?

According to Halo Surface Signal, this plugin is designed for the front end of websites, making its functions naturally accessible to public web traffic. Because the component is intended for visitor interaction, any site using this plugin version is likely exposed to network-based queries from anywhere on the internet.

When should I take action for this vulnerability?

You should prioritize assessing this immediately if you manage a WordPress site. Begin by creating an inventory of all active plugins to confirm if Product Filter by WBW is installed. Once identified, evaluate the plugin's role in your site and coordinate with your team to apply the necessary software updates to secure the database.

References