CVE-2026-57810
HIGHWordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-57810. PoCs published by incogbyte.
AI-analyzed exploit summary Authenticated blind SQL injection in APIExperts Square for WooCommerce (woosquare) <= 4.7.4 via unescaped product variation name in the 'update_square_to_woo' AJAX action. The exploit demonstrates timing-based proof-of-concept by injecting SLEEP() into raw SQL queries.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.
Exploits (1)
Authenticated blind SQL injection in APIExperts Square for WooCommerce (woosquare) <= 4.7.4 via unescaped product variation name in the 'update_square_to_woo' AJAX action. The exploit demonstrates timing-based proof-of-concept by injecting SLEEP() into raw SQL queries.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L