SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59537

HIGH · CVSS 7.6 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The vulnerability allows for SQL injection attacks in the Sender plugin for WooCommerce, affecting versions up to 2.10.22, which could enable attackers to manipulate database queries and potentially access sensitive data. This high-severity flaw poses a significant risk to e-commerce sites using the affected plugin, making it crucial for administrators of these systems to prioritize patching or upgrading to mitigate potential data breaches.

CVE
CVE-2026-59537
Severity
HIGH
CVSS
7.6
EPSS
0.27%

Original NVD Description

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.