{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/lumise-product-designer-for-woocommerce--2.1.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-9713"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Lumise Product Designer for WooCommerce (\u003c= 2.1.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","woocommerce","sql-injection","web-vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["Lumise","WordPress"],"content_html":"\u003cp\u003eA critical SQL Injection vulnerability, tracked as CVE-2026-9713, affects the Lumise Product Designer for WooCommerce plugin for WordPress, impacting all versions up to and including 2.1.1. This flaw allows unauthenticated attackers to exploit the 'id' and 'table' parameters found within an uploaded cart JSON file. These parameters are handled by the plugin's checkout AJAX action, specifically within the \u003ccode\u003efind_resource()\u003c/code\u003e function, where they are insufficiently escaped before being directly appended to a raw SQL query. Neither \u003ccode\u003ewp_magic_quotes\u003c/code\u003e nor \u003ccode\u003e$wpdb-\u0026gt;prepare()\u003c/code\u003e adequately protect these inputs. Attackers can leverage this vulnerability to inject additional SQL queries, enabling them to extract sensitive information from the underlying WordPress database, posing a significant risk to data confidentiality.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker crafts a malicious JSON file containing specially formatted \u003ccode\u003eid\u003c/code\u003e and \u003ccode\u003etable\u003c/code\u003e parameters with SQL injection payloads.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an HTTP POST request to the \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e endpoint on the vulnerable WordPress site, specifying the \u003ccode\u003eaction=lumise_checkout\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe crafted JSON file is included in the request body as part of the \u0026quot;uploaded cart\u0026quot; data.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003elumise_checkout\u003c/code\u003e AJAX action processes the request and calls the \u003ccode\u003efind_resource()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eInside \u003ccode\u003efind_resource()\u003c/code\u003e, the malicious \u003ccode\u003eid\u003c/code\u003e and \u003ccode\u003etable\u003c/code\u003e parameters from the JSON file are directly interpolated into a raw SQL query without proper escaping or sanitization.\u003c/li\u003e\n\u003cli\u003eThe injected SQL commands execute against the WordPress database, allowing the attacker to bypass authentication and retrieve sensitive information.\u003c/li\u003e\n\u003cli\u003eThe attacker receives database query results, potentially containing user credentials, customer data, or other proprietary information, within the server's response.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-9713 allows unauthenticated attackers to extract sensitive data directly from the WordPress database. This can include user details, hashed passwords, order information, and other proprietary business data stored by the WooCommerce plugin. The compromise of such information can lead to severe privacy breaches, financial fraud, reputational damage, and further exploitation of the affected website and its users. Given the unauthenticated nature of the vulnerability, any internet-facing WordPress site using the affected plugin is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-9713 on all affected WordPress installations running the Lumise Product Designer for WooCommerce plugin immediately by updating to a version greater than 2.1.1.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to your SIEM to detect attempts at exploiting CVE-2026-9713.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP POST requests to \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e containing \u003ccode\u003eaction=lumise_checkout\u003c/code\u003e and suspicious SQL-like strings in the request body.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T08:18:58Z","date_published":"2026-07-23T08:18:58Z","id":"https://feed.craftedsignal.io/briefs/2026-07-lumise-woocommerce-sqli/","summary":"The Lumise Product Designer for WooCommerce plugin for WordPress, in versions up to and including 2.1.1, is vulnerable to SQL Injection via the 'id' and 'table' parameters within an uploaded cart JSON file processed by the checkout AJAX action, allowing unauthenticated attackers to extract sensitive database information.","title":"CVE-2026-9713: Lumise Product Designer for WooCommerce Plugin SQL Injection","url":"https://feed.craftedsignal.io/briefs/2026-07-lumise-woocommerce-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Lumise Product Designer for WooCommerce (\u003c= 2.1.1)","version":"https://jsonfeed.org/version/1.1"}