WPML Multilingual & Multicurrency for WooCommerce <= 5.5.8 - Authenticated (Shop Manager+) SQL Injection via 'currency' Parameter

Medium 4.9 CWE-89Fixed in 5.6.3
ID
WPSEC-2026-0648
Plugin
WPML Multilingual & Multicurrency for WooCommerce (woocommerce-multilingual)
Affected
from 4.11.2 before 5.6.3
Remediation
Update to 5.6.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-89
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-08
Attack surface
WPML Multilingual & Multicurrency for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The WPML Multilingual & Multicurrency for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'currency' parameter of the WooCommerce REST API sales reports in versions 4.11.2 up to, and including, 5.5.8. This is due to the value being placed into the report query's WHERE clause without escaping or a prepared statement. This makes it possible for authenticated attackers with access to WooCommerce reports, such as Shop Managers, to append additional SQL queries to existing queries and extract sensitive information from the database. Only sites with multi-currency enabled are affected.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0