CVE · High

CVE-2026-12753 — Advance Product Search- Voice & Ajax Search for WooCommerce [th-advance-product-search] < 1.4.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12753 Advance Product Search- Voice & Ajax Search for WooCommerce [th-advance-product-search] < 1.4.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 1.4.5 1.4.5 2026-07-15

CVE-2026-12753

The Advance Product Search- Voice & Ajax Search plugin for WooCommerce has a security flaw in versions up to 1.4.4, which allows malicious input to inject arbitrary SQL code into database queries. This occurs because user-submitted parameters are not properly sanitized, enabling attackers to craft and execute additional SQL statements without authentication. As a result, sensitive data within the database can be accessed by unauthorized parties.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.