What is CVE-2026-32552?
CVE-2026-32552 is a Subscriber-level SQL Injection vulnerability in YITH WooCommerce Membership Premium plugin versions up to 2.33.0. It allows authenticated low-privileged users to manipulate database queries and potentially access sensitive data. Updating to a patched version is strongly recommended.
Azərbaycanca: CVE-2026-32552, YITH WooCommerce Membership Premium plagininin 2.33.0 və əvvəlki versiyalarında aşkarlanmış, Subscriber səviyyəli istifadəçilərə SQL Injection hücumu etməyə imkan verən boşluqdur. Bu zəiflik autentifikasiya olunmuş aşağı səviyyəli istifadəçilərə verilənlər bazasına müdaxilə edərək həssas məlumatları oxumağa şərait yaradır. Təsirə məruz qalmamaq üçün plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which plugin is affected by CVE-2026-32552?
This vulnerability affects the YITH WooCommerce Membership Premium plugin in versions up to 2.33.0.
What level of privilege does an attacker need to exploit CVE-2026-32552?
An attacker needs to have authenticated low-level user privileges, such as those of a Subscriber.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.