Skip to content

Known CVE

WCAPF WooCommerce Ajax Product Filter - SQL Injection

WCAPF WooCommerce Ajax Product Filter <= 4.2.3 contains a time-based SQL injection caused by insufficient escaping of the 'post-author' parameter, letting unauthenticated attackers extract sensitive database information remotely.

CVE-2026-3396

High2026CVSS 7.5CWE-89

sqli · wp-plugin · wc-ajax-product-filter · woocommerce · wordpress

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website