{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/woocommerce-lottery/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18884"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WooCommerce Lottery"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sqli","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WooCommerce Lottery plugin for WordPress, in all versions up to and including 2.2.9, contains a critical security vulnerability identified as CVE-2026-18884. This flaw is a time-based SQL injection vulnerability originating from insufficient escaping and a lack of prepared statements within the plugin's code. Specifically, the 'orderby' and 'order' GET parameters are improperly sanitized before being used in SQL queries. An unauthenticated attacker can exploit this by injecting malicious SQL commands into these parameters, forcing the database to perform time-delayed operations. By measuring the response time of the web server, an attacker can incrementally infer and exfiltrate data from the underlying WordPress database, including sensitive user information, configuration data, or authentication tokens. Given the prevalence of WordPress and the nature of the WooCommerce ecosystem, this vulnerability poses a significant risk to the integrity and confidentiality of affected e-commerce environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify sites running the WooCommerce Lottery plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET request targeting a page utilizing the plugin's sorting functionality.\u003c/li\u003e\n\u003cli\u003eAttacker injects a time-based SQL payload (e.g., SLEEP() or BENCHMARK()) into the 'orderby' or 'order' query parameters.\u003c/li\u003e\n\u003cli\u003eThe web server receives the request and processes the malicious parameter through the vulnerable plugin code.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected command, causing a measurable time delay in the server's response.\u003c/li\u003e\n\u003cli\u003eAttacker observes the response time variance to confirm the vulnerability and begins automated data exfiltration.\u003c/li\u003e\n\u003cli\u003eAttacker successfully extracts sensitive database tables, such as user credentials or customer transaction history.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to bypass application-level authentication and interact directly with the WordPress backend database. Potential damage includes full exfiltration of customer records, PII, and administrative credentials, leading to site takeover or financial data theft.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WooCommerce Lottery plugin to the latest version available beyond 2.2.9 immediately to remediate CVE-2026-18884.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous GET requests containing SQL syntax patterns such as 'ORDER BY', 'SLEEP', 'BENCHMARK', or case-conversion functions in the query string.\u003c/li\u003e\n\u003cli\u003eDeploy a Web Application Firewall (WAF) to block requests containing SQL injection payloads targeting 'orderby' or 'order' parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T16:21:21Z","date_published":"2026-08-26T16:21:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-woocommerce-sqli/","summary":"The WooCommerce Lottery plugin for WordPress is vulnerable to unauthenticated time-based SQL injection via the 'orderby' and 'order' GET parameters, allowing attackers to extract sensitive database information.","title":"Unauthenticated SQL Injection in WooCommerce Lottery Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-woocommerce-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - WooCommerce Lottery","version":"https://jsonfeed.org/version/1.1"}