← WordPress Vulnerabilities
WordPress security by component

WCAPF – Ajax Product Filter for WooCommerce

WCAPF – Ajax Product Filter for WooCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: wc-ajax-product-filter

CVE-2026-3396: WCAPF – Ajax Product Filter for WooCommerce: SQL injection

WCAPF – Ajax Product Filter for WooCommerce is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.2.3.

PublishedApr 08, 2026
Known safe version> 4.2.3
Safe version
Apr 08, 2026 CVE-2026-3396
WCAPF – Ajax Product Filter for WooCommerce: SQL injection
WCAPF – Ajax Product Filter for WooCommerce is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.2.3.
> 4.2.3
CVE7.5
NVDPending