Record summary

CVE-2026-39494 has a selected CVSS score of 9.3 (critical).

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 11, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Product Filter by WBW

Browse WBW Plugins / Product Filter by WBWwoo-product-filter

Default status: unaffected

CVE ListThrough 3.1.2affected
VulnCheckVersion data not supplied

References

2