Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
Published: 2026-10-01
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: SQL Injection Leading to Database Compromise
Action: Patch
AI Analysis

Impact

The vulnerability arises from improper neutralization of special elements in an SQL command, allowing blind SQL injection within the BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin. An attacker could extract or modify sensitive data stored in the WordPress database, potentially leading to confidentiality or integrity breaches. The flaw stems from insufficient input validation (CWE‑89) and, if exploited successfully, could provide an attacker with unauthorized database access.

Affected Systems

The affected product is VillaTheme’s BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin, deployed within WordPress sites. Versions up to and including 1.0.28 are vulnerable. Users running any of these releases, regardless of whether the plugin is used heavily or minimally, are at risk unless patched.

Risk and Exploitability

With a CVSS score of 8.5, this issue is considered High severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, suggesting no known public exploitation yet. The attack is likely carried out via specially crafted input to the plugin’s forms or endpoints; it may require authenticated access to submit parameters, but the description does not state otherwise. Given the nature of the flaw, exploitation could result in full compromise of the underlying database.

Generated by OpenCVE AI on October 1, 2026 at 14:27 UTC.

Remediation

Vendor Solution

Update the WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin to the latest available version (at least 1.0.29).


OpenCVE Recommended Actions

  • Update the BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin to version 1.0.29 or later.
  • If an update is not immediately possible, configure the plugin so that only administrators can submit or view the forms that accept user input.
  • Implement or enforce database‑level safeguards such as parameterized queries and least‑privilege credentials to reduce the impact of any remaining injection vectors.

Generated by OpenCVE AI on October 1, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Villatheme
Villatheme buildkit – Product Builder For Woocommerce – Custom Pc Builder
Wordpress-extensions
Wordpress-extensions buildkit-product Builder For Woocommerce-custom Pc Builder
Vendors & Products Villatheme
Villatheme buildkit – Product Builder For Woocommerce – Custom Pc Builder
Wordpress-extensions
Wordpress-extensions buildkit-product Builder For Woocommerce-custom Pc Builder

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
Title WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Villatheme Buildkit – Product Builder For Woocommerce – Custom Pc Builder
Wordpress-extensions Buildkit-product Builder For Woocommerce-custom Pc Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T13:16:47.620Z

Reserved: 2026-09-29T00:15:56.341Z

Link: CVE-2026-102379

cve-icon Vulnrichment

Updated: 2026-10-01T13:16:33.669Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T13:17:07.297

Modified: 2026-10-01T14:34:35.357

Link: CVE-2026-102379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:34:34Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')