GHSA-r5c2-6qm5-q499HighCVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
🔗 CVE IDs covered (1)
📋 Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
🔗 References (3)
- https://nvd.nist.gov/vuln/detail/CVE-2026-102379
- https://patchstack.com/database/wordpress/plugin/woo-product-builder/vulnerability/wordpress-buildkit-product-builder-for-woocommerce-custom-pc-builder-plugin-1-0-28-sql-injection-vulnerability?_s_id=cve
- https://github.com/advisories/GHSA-r5c2-6qm5-q499