What is CVE-2026-59537?
CVE-2026-59537 is an Administrator SQL Injection vulnerability found in the Sender – Newsletter, SMS and Email Marketing Automation plugin for WooCommerce, affecting versions <= 2.10.22. This flaw allows an authenticated administrator to manipulate database queries, potentially leading to data compromise. Users are strongly advised to update the plugin immediately.
Azərbaycanca: CVE-2026-59537, Sender plagininin WooCommerce üçün 2.10.22 və daha əvvəlki versiyalarında administrator panelində aşkarlanmış SQL Injection zəifliyidir. Bu zəiflik autentifikasiya olunmuş administratorun xüsusi sorğular vasitəsilə verilənlər bazasına müdaxilə etməsinə imkan verir. Plagindən istifadə edən sayt sahibləri dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which plugin and up to which version does CVE-2026-59537 exist?
CVE-2026-59537 exists in the Sender – Newsletter, SMS and Email Marketing Automation plugin for WooCommerce, affecting versions 2.10.22 and below.
Is authentication required to exploit CVE-2026-59537?
Yes, this vulnerability is an Administrator SQL Injection flaw, meaning it requires an authenticated administrator account to manipulate database queries.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.