CVE-2026-57810

HIGH

WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-57810. PoCs published by incogbyte.

AI-analyzed exploit summary Authenticated blind SQL injection in APIExperts Square for WooCommerce (woosquare) <= 4.7.4 via unescaped product variation name in the 'update_square_to_woo' AJAX action. The exploit demonstrates timing-based proof-of-concept by injecting SLEEP() into raw SQL queries.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.

Exploits (1)

github WORKING POC 3 stars
by incogbyte · pythonpoc
https://github.com/incogbyte/wp-cve-exploits/tree/main/CVE-2026-57810

Authenticated blind SQL injection in APIExperts Square for WooCommerce (woosquare) <= 4.7.4 via unescaped product variation name in the 'update_square_to_woo' AJAX action. The exploit demonstrates timing-based proof-of-concept by injecting SLEEP() into raw SQL queries.

Classification
Working Poc 99%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: APIExperts Square for WooCommerce (woosquare) <= 4.7.4
Auth required
Prerequisites: Authenticated user with access to the plugin's settings page (nonce required) · Plugin's 'Items Sync' module must be active · At least one row in wp_woocommerce_attribute_taxonomies for timing signal
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →

Scores

CVSS v3 8.5
EPSS 0.0021
EPSS Percentile 10.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Saad Iqbal/APIExperts Square for WooCommerce < 4.7.4
Published Jul 13, 2026
Tracked Since Jul 13, 2026