LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-31920

CVE-2026-31920 - Vulnerability Analysis

CriticalCVSS: 9.3

Last Updated: March 26, 2026

Devteam HaywoodTech Product Rearrange for WooCommerce - SQL Injection

Published: March 25, 2026Updated: March 26, 2026Remote Exploitable

Overview

Devteam HaywoodTech Product Rearrange for WooCommerce <= 1.2.2 contains an SQL injection caused by improper neutralization of special elements in SQL commands, letting attackers perform blind SQL injection remotely, exploit requires crafted requests.

Severity & Score

Severity: Critical
CVSS Score: 9.3

Impact

Attackers can execute blind SQL injection to extract or manipulate database information, potentially compromising data integrity and confidentiality.

Mitigation

Update to the latest version beyond 1.2.2.

Details

CVE ID
CVE-2026-31920
Severity
Critical
CVSS Score
9.3
Type
sql_injection
Status
new

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L