# YITH WooCommerce Product Add-Ons <= 4.34.0 - Authenticated (Shop Manager+) SQL Injection via 's' Parameter

- **ID:** WPSEC-2026-0493
- **Plugin:** YITH WooCommerce Product Add-Ons (`yith-woocommerce-product-add-ons`), https://wordpress.org/plugins/yith-woocommerce-product-add-ons/
- **Affected versions:** from 4.29.1 before 4.34.1
- **Fixed in:** 4.34.1 (Update to 4.34.1 or later.)
- **Severity:** Medium 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-89
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/yith-woocommerce-product-add-ons
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0493/

## Description

The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to SQL Injection via the 's' parameter of the add-on blocks list in versions 4.29.1 up to, and including, 4.34.0, due to an incomplete fix for CVE-2026-42383. The user-supplied search term is placed inside a LIKE clause without escaping or a prepared statement in the default, unfiltered blocks list. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to append additional SQL queries to existing queries that can be used to extract sensitive information from the database.

## References

- https://wpsec.com/vuln/WPSEC-2026-0493/
- https://plugins.svn.wordpress.org/yith-woocommerce-product-add-ons/tags/4.34.1/
- https://wordpress.org/plugins/yith-woocommerce-product-add-ons/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0493/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
