Sceawere
Vulnerability Detail
CVE-2026-32580UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated SQL Injection WooCommerce Lottery
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 16h ago
- Vendor
- wpgenie
- Product
- WooCommerce Lottery
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:43.780Z",
"pubdate": "2026-10-06T09:17:43.780Z",
"executiveSummary": "WooCommerce Lottery versions 2.2.9 and below are susceptible to an unauthenticated SQL injection vulnerability.\nThis security flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying WordPress database.\nThe vulnerability resides in the improper sanitization of user-supplied input before it is included in database queries.\nSuccessful exploitation grants an attacker the ability to bypass authentication mechanisms, disclose sensitive data, modify database content, or escalate privileges.\nThe risk is critical, as it requires no prior authentication or administrative access, making it highly attractive for automated scanning and exploitation tools.\nThe impact includes full database compromise, unauthorized access to customer information, and potential complete site takeover by an external actor.",
"technicalDetails": "The vulnerability originates from the failure of the WooCommerce Lottery plugin to correctly sanitize and validate input parameters before utilizing them in database operations. Specifically, the affected code paths fail to implement parameterized queries or adequate input filtering, allowing an attacker to inject arbitrary SQL statements through maliciously crafted HTTP requests.\nThe attack flow begins when an unauthenticated user sends a specifically formatted request to a vulnerable endpoint within the plugin. Because the input parameter is not properly escaped or prepared, the database management system interprets the injected SQL fragments as part of the intended query. This enables the attacker to perform UNION-based attacks, blind SQL injection, or error-based injection to extract sensitive information stored in the WordPress tables.\nIn a typical attack scenario, an attacker might inject malicious SQL syntax into a GET or POST parameter. By successfully crafting a payload, the attacker can manipulate the WHERE clause of a SQL query, allowing them to bypass logic checks or join tables that should be inaccessible to unauthorized users. This capability allows the attacker to retrieve hashed administrator credentials, customer personally identifiable information (PII), or plugin-specific configuration settings.\nThe scope of the impact is broad due to the inherent structure of WordPress databases. By leveraging the database connection established by the plugin, an attacker can manipulate table structures, update administrator account passwords, or inject malicious scripts into the database that may later be executed via Cross-Site Scripting (XSS) if retrieved by other site components. Because the vulnerability is reachable without authentication, it exposes the system to wide-scale automated attacks from any network-connected actor.\nFurthermore, the persistence of this vulnerability in versions 2.2.9 and below necessitates immediate remediation, as the lack of input validation remains a critical failure point in the plugin's data handling logic. Any instance where user-controllable input reaches database query functions without going through proper WordPress database abstraction layers (such as the $wpdb->prepare() function) remains a high-risk area for exploitation."
}