What is CVE-2026-9713?
CVE-2026-9713: The Lumise Product Designer for WooCommerce plugin up to version 2.1.1 contains an SQL Injection vulnerability. An attacker can exploit the 'id' and 'table' parameters within an uploaded cart JSON file during the checkout AJAX action, potentially gaining unauthorized database access. Immediate plugin update is strongly recommended.
Azərbaycanca: CVE-2026-9713: Lumise Product Designer for WooCommerce plaqini versiya 2.1.1-ə qədər SQL Injection zəifliyinə malikdir. Hücumçu 'id' və 'table' parametrləri vasitəsilə səbət JSON faylına zərərli kod yeridərək, checkout AJAX əməliyyatı zamanı verilənlər bazasını manipulyasiya edə bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Lumise Product Designer for WooCommerce plugin are affected by CVE-2026-9713?
This SQL Injection vulnerability affects all versions of the plugin up to version 2.1.1.
Through which parameters in the cart JSON file can an attacker exploit the CVE-2026-9713 vulnerability to manipulate the database?
An attacker can exploit the 'id' and 'table' parameters within a maliciously crafted cart JSON file during the checkout AJAX action to manipulate the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.