VidShop for WooCommerce <= 1.1.4 - SQL Injection
CVE-2026-0702
Verified
Description
VidShop – Shoppable Videos for WooCommerce plugin for WordPress <= 1.1.4 contains a time-based SQL injection caused by insufficient escaping of the 'fields' parameter, letting unauthenticated attackers extract sensitive database information.
Severity
High
CVSS Score
7.5
Exploit Probability
2%
Published Date
September 9, 2026
Template Author
str4k3r
CVE-2026-0702.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-0702
CWE ID:
cwe-89
References
https://plugins.trac.wordpress.org/browser/vidshop-for-woocommerce/trunk/includes/rest-api/v1/class-videos-controller.php#L297https://plugins.trac.wordpress.org/browser/vidshop-for-woocommerce/trunk/includes/utils/class-query-builder.php#L778https://www.wordfence.com/threat-intel/vulnerabilities/id/a61d8d2a-742f-45f1-9146-f733b80ef195?source=cve
Remediation Steps
Update to the latest version of VidShop – Shoppable Videos for WooCommerce plugin for WordPress.