Sceawere
Vulnerability Detail
CVE-2026-89297UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Loja Automática SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Loja Automática
- Attack Type
- CWE-89 SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Loja Automática WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-11T07:17:28.670Z",
"pubdate": "2026-10-11T07:17:28.670Z",
"executiveSummary": "The Loja Automática WordPress plugin through version 1.0.0 is susceptible to an unauthenticated SQL injection (SQLi) vulnerability. This flaw arises from the improper sanitization and escaping of user-supplied input before it is incorporated into database queries.\nThe vulnerability allows an unauthenticated remote attacker to manipulate SQL queries executed by the backend database. By injecting malicious SQL syntax through affected parameters, an attacker can bypass security controls, extract sensitive information from the database, or potentially modify stored data.\nThe impact includes full database compromise, unauthorized access to administrative credentials, and potential remote code execution via database-level operations. Given that the attack requires no authentication, it presents a critical risk to the confidentiality, integrity, and availability of the WordPress site. Organizations utilizing this plugin are advised to disable or remove the software until a patch is verified as available.",
"technicalDetails": "The root cause of this vulnerability is the failure of the Loja Automática plugin to employ secure database query practices when handling user-supplied data. Specifically, the plugin constructs SQL queries by concatenating unsanitized input directly into query strings, rather than utilizing parameterized queries or prepared statements provided by the WordPress wpdb class.\nAn attacker can exploit this by crafting a malicious HTTP request containing SQL payloads within the vulnerable parameter. Because the application logic fails to validate or escape this input, the database interpreter treats the payload as legitimate SQL code rather than literal data, allowing the attacker to alter the query's execution logic.\nThe attack flow begins when an unauthenticated user submits a specially crafted HTTP GET or POST request to the plugin’s entry point. The application extracts the input from the request and inserts it into a SQL statement without sufficient sanitization. For example, by inserting UNION-based SELECT statements, an attacker can append results from internal database tables, such as the 'wp_users' table, to the application's output. This allows for the exfiltration of usernames, hashed passwords, and other sensitive configuration data.\nFurthermore, the vulnerability is not restricted to read-only operations. If the database user configured for the WordPress site has sufficient permissions, an attacker might execute stacked queries or perform Data Manipulation Language (DML) operations. This could lead to the modification of existing administrator accounts, the creation of new backdoored accounts, or the deletion of site content.\nThe exposure is network-wide, as the vulnerable endpoint is accessible without prior authentication, enabling automated exploitation by remote actors. Because the plugin processes these parameters server-side, the backend database is directly exposed to the injected malicious syntax. The vulnerability exists in all plugin versions through 1.0.0, and there are currently no specific input validation routines identified to prevent these injection vectors. Successful exploitation results in complete loss of data confidentiality and integrity, effectively granting the attacker control over the underlying data store."
}