WCAPF WooCommerce Ajax Product Filter <= 4.2.3 contains a time-based SQL injection caused by insufficient escaping of the 'post-author' parameter, letting unauthenticated attackers extract sensitive database information remotely.
id: CVE-2026-3396
info:
name: WCAPF WooCommerce Ajax Product Filter - SQL Injection
author: the
...