CVE-2026-3396Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-08: 1Mentions · 2026-04-12: 1Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-14: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-14: 104-0804-1204-14
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-3396 - high 🚨 WCAPF WooCommerce Ajax Product Filter - SQL Injection > WCAPF WooCommerce Ajax Product Filter <= 4.2.3 contains a time-based SQL injection ca... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-3396 @pdnuclei #NucleiTemplates #cve

    Post summary

    ProjectDiscovery disclosed CVE‑2026‑3396 as a high‑severity time‑based SQL injection affecting WCAPF WooCommerce Ajax Product Filter v4.2.3 and below, providing a link that likely contains a PoC but no details on active exploitation or available patches.

    00001186
    931 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3396 WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due… https://www.cve.org/CVERecord?id=CVE-2026-3396

    Post summary

    A time‑based SQL injection vulnerability has been disclosed in WooCommerce Ajax Product Filter versions up to 4.2.3, with no known exploits, patches, or false‑positive claims reported.

    00000108
    57.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3396 - WCAPF - WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection Intel Report: https://ift.tt/iYGuBIS

    Post summary

    The alert identifies an unauthenticated time‑based SQL injection in WooCommerce Ajax Product Filter v4.2.3 and earlier, with no proof‑of‑concept, exploit tool, or patch disclosed.

    0000035
    281 followersView on X

Explore more