Sceawere

Vulnerability Detail

CVE-2026-32580UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated SQL Injection WooCommerce Lottery

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
16h ago
Vendor
wpgenie
Product
WooCommerce Lottery
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-06T09:17:43.780Z",
  "pubdate": "2026-10-06T09:17:43.780Z",
  "executiveSummary": "WooCommerce Lottery versions 2.2.9 and below are susceptible to an unauthenticated SQL injection vulnerability.\nThis security flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying WordPress database.\nThe vulnerability resides in the improper sanitization of user-supplied input before it is included in database queries.\nSuccessful exploitation grants an attacker the ability to bypass authentication mechanisms, disclose sensitive data, modify database content, or escalate privileges.\nThe risk is critical, as it requires no prior authentication or administrative access, making it highly attractive for automated scanning and exploitation tools.\nThe impact includes full database compromise, unauthorized access to customer information, and potential complete site takeover by an external actor.",
  "technicalDetails": "The vulnerability originates from the failure of the WooCommerce Lottery plugin to correctly sanitize and validate input parameters before utilizing them in database operations. Specifically, the affected code paths fail to implement parameterized queries or adequate input filtering, allowing an attacker to inject arbitrary SQL statements through maliciously crafted HTTP requests.\nThe attack flow begins when an unauthenticated user sends a specifically formatted request to a vulnerable endpoint within the plugin. Because the input parameter is not properly escaped or prepared, the database management system interprets the injected SQL fragments as part of the intended query. This enables the attacker to perform UNION-based attacks, blind SQL injection, or error-based injection to extract sensitive information stored in the WordPress tables.\nIn a typical attack scenario, an attacker might inject malicious SQL syntax into a GET or POST parameter. By successfully crafting a payload, the attacker can manipulate the WHERE clause of a SQL query, allowing them to bypass logic checks or join tables that should be inaccessible to unauthorized users. This capability allows the attacker to retrieve hashed administrator credentials, customer personally identifiable information (PII), or plugin-specific configuration settings.\nThe scope of the impact is broad due to the inherent structure of WordPress databases. By leveraging the database connection established by the plugin, an attacker can manipulate table structures, update administrator account passwords, or inject malicious scripts into the database that may later be executed via Cross-Site Scripting (XSS) if retrieved by other site components. Because the vulnerability is reachable without authentication, it exposes the system to wide-scale automated attacks from any network-connected actor.\nFurthermore, the persistence of this vulnerability in versions 2.2.9 and below necessitates immediate remediation, as the lack of input validation remains a critical failure point in the plugin's data handling logic. Any instance where user-controllable input reaches database query functions without going through proper WordPress database abstraction layers (such as the $wpdb->prepare() function) remains a high-risk area for exploitation."
}
CVE-2026-32580: Unauthenticated SQL Injection WooCommerce Lottery (HIGH Severity, CVSS: 7.5) | Sceawere