Skip to main content
Vulnerability Database/CVE-2026-87770

CVE-2026-87770: Price Drop Alert for WooCommerce SQLi Flaw

CVE-2026-87770 is a SQL injection vulnerability in the Price Drop Alert for WooCommerce WordPress plugin that allows unauthenticated attackers to extract sensitive database information. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-87770 Overview

CVE-2026-87770 is an unauthenticated SQL injection vulnerability in the Price Drop Alert for WooCommerce WordPress plugin through version 1.1. The plugin fails to sanitize and escape parameters before passing them to a SQL query in an AJAX action exposed to unauthenticated users. Attackers can inject arbitrary SQL statements over the network without any authentication or user interaction. Successful exploitation allows extraction of sensitive data from the WordPress database, including user credentials, session tokens, and customer records stored by WooCommerce. The vulnerability is classified under [CWE-89] (Improper Neutralization of Special Elements used in an SQL Command).

Critical Impact

Unauthenticated remote attackers can extract arbitrary data from the WordPress database, including WooCommerce customer records and administrator credential hashes.

Affected Products

  • Price Drop Alert for WooCommerce WordPress plugin, all versions through 1.1
  • WordPress sites running WooCommerce with the affected plugin enabled
  • Any hosting environment exposing the vulnerable AJAX endpoint to the public internet

Discovery Timeline

  • 2026-09-18 - CVE-2026-87770 published to the National Vulnerability Database
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-87770

Vulnerability Analysis

The vulnerability resides in an AJAX handler registered with WordPress wp_ajax_nopriv_* hooks, which makes the endpoint reachable by unauthenticated visitors. User-supplied parameters flow directly into a SQL query without being processed through $wpdb->prepare() or WordPress sanitization helpers such as esc_sql() or absint(). This constitutes a textbook injection flaw under [CWE-89].

The scope change captured in the CVSS vector reflects that a successful attack against the plugin can expose data across the entire WordPress database, not just plugin-owned tables. Attackers can enumerate rows from wp_users, wp_usermeta, and WooCommerce order tables. The current EPSS probability sits at 0.445%, indicating limited observed exploitation, but the low barrier to entry raises the practical risk for internet-facing storefronts.

Root Cause

The root cause is missing input sanitization and the absence of parameterized queries in the AJAX action handler. The plugin concatenates request parameters directly into the SQL string. Because the endpoint is registered for unauthenticated use, no capability check or nonce verification blocks the request path before it reaches the database layer.

Attack Vector

An attacker sends a crafted HTTP POST or GET request to /wp-admin/admin-ajax.php specifying the vulnerable plugin action and a malicious payload in the affected parameter. The payload can use UNION-based, boolean-based, or time-based SQL injection techniques to enumerate schema, extract rows, and exfiltrate credentials. No authentication, cookies, or user interaction are required. See the WPScan Vulnerability Report for additional technical context.

Detection Methods for CVE-2026-87770

Indicators of Compromise

  • Unexpected requests to /wp-admin/admin-ajax.php containing SQL keywords such as UNION, SELECT, SLEEP(, BENCHMARK(, or encoded variants in query parameters
  • Bursts of AJAX requests from a single source IP targeting the Price Drop Alert plugin action name
  • Database error entries in PHP or web server logs referencing malformed SQL originating from plugin queries
  • Unusual outbound data volumes from the web server correlating with sustained AJAX traffic

Detection Strategies

  • Deploy Web Application Firewall (WAF) rules that inspect admin-ajax.php parameters for SQL metacharacters and known injection payloads
  • Enable MySQL general query logging temporarily to identify queries containing untypical operators against WooCommerce tables
  • Correlate WordPress access logs with authentication logs to identify credential harvesting attempts that follow suspicious AJAX activity

Monitoring Recommendations

  • Alert on repeated 500-series HTTP responses from admin-ajax.php that indicate query parsing failures
  • Monitor for new administrative user creation or password resets shortly after anomalous AJAX traffic
  • Track outbound connections from the web server to unknown destinations, which may indicate exfiltration of extracted database content

How to Mitigate CVE-2026-87770

Immediate Actions Required

  • Deactivate and remove the Price Drop Alert for WooCommerce plugin until a patched release is verified
  • Block or rate-limit unauthenticated requests to admin-ajax.php actions associated with the plugin at the WAF or reverse proxy
  • Rotate WordPress administrator passwords, WooCommerce API keys, and database credentials if any exploitation indicators are present
  • Audit wp_users and wp_options tables for unauthorized modifications

Patch Information

No vendor patch is referenced in the enriched CVE data at the time of publication. Site operators should monitor the WPScan Vulnerability Report and the WordPress.org plugin repository for an updated release beyond version 1.1. Until a fixed version is published, removal of the plugin is the only reliable remediation.

Workarounds

  • Remove the plugin directory from wp-content/plugins/ to prevent the AJAX action from being registered
  • Add a WAF signature that rejects requests to admin-ajax.php where the action parameter matches the vulnerable plugin handler
  • Restrict database user privileges so that the WordPress account has only the minimum rights needed, limiting the blast radius of a successful injection
bash
# Example ModSecurity rule to block requests to the vulnerable AJAX action
SecRule REQUEST_URI "@contains /wp-admin/admin-ajax.php" \
    "chain,id:1008777,phase:2,deny,status:403,log,msg:'Block CVE-2026-87770 exploitation attempt'"
    SecRule ARGS:action "@rx (?i)price_drop_alert" \
        "chain"
        SecRule ARGS "@rx (?i)(union.+select|sleep\(|benchmark\(|information_schema)" \
            "t:none,t:urlDecodeUni"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.