S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 14, 2026

CVE-2026-3396 Scanner

CVE-2026-3396 Scanner - SQL Injection vulnerability in WCAPF WooCommerce Ajax Product Filter

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-3396
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WCAPF – Ajax Product Filter for WooCommerceby shamimmoeen
0
Updated Aug 22, 2026View on NVD →
Detail

WCAPF WooCommerce Ajax Product Filter is a popular plugin used by online retailers utilizing WooCommerce on WordPress to enhance their product filtering capabilities. This plugin is deployed by website administrators and developers looking to streamline the user experience in online shopping environments. Its primary function is to allow customers to filter products through various criteria, making it easier for them to navigate large inventories. The plugin is regularly updated to add features and improve functionality, ensuring seamless integration with other WooCommerce components. However, maintaining the security and stability of the plugin is crucial due to its impact on user experience and data handling processes.

The SQL Injection vulnerability detected in WCAPF WooCommerce Ajax Product Filter arises from inadequate input validation on the 'post-author' parameter. This allows unauthenticated attackers to execute arbitrary SQL queries on the database through manipulated HTTP requests. SQL Injection is a critical security flaw that can lead to unauthorized data exposure and potential data manipulation. By exploiting this vulnerability, attackers could access sensitive information, such as user credentials and private customer data, without authorization. Preventing SQL Injection typically requires parameterized queries and robust input sanitation mechanisms.

Technical details surrounding this SQL Injection vulnerability involve the 'filter_post_author' parameter, which is poorly sanitized, allowing for time-based SQL query execution. Attackers craft requests that utilize the SLEEP function in SQL, effectively verifying the presence of the vulnerability by observing request delays. Successful exploitation demonstrates the vulnerability's impact by extracting database responses indirectly through timing discrepancies. This points to a likely lack of the proper escape mechanism required to sanitize user inputs, exposing the database to externally influenced SQL logic.

Exploitation of this vulnerability can lead to significant risks, including unauthorized access to sensitive data stored within the website's database. This could result in data breaches affecting both the business and its customers, such as exposure of personal information and financial records. Moreover, the compromised data integrity might allow attackers to manipulate store content or inject malicious logic. This kind of exposure can severely damage a business's reputation, lead to financial losses, and result in legal ramifications if customer data protection regulations are violated.

REFERENCES

Solution Advice
  • Upgrade WCAPF WooCommerce Ajax Product Filter to a version later than 4.2.3 to close the vulnerability.
  • Ensure that inputs on all parameters are properly sanitized and validated, reducing malicious input risk.
  • Utilize application firewalls to detect and block SQL injection attempts.
  • Regularly review and update plugins to adapt to the latest security practices.
  • Conduct periodic security audits of plugins and associated WordPress installations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.