Description
The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2026-09-19
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated SQL injection that can exfiltrate data
Action: Patch
AI Analysis

Impact

The GoPay for WooCommerce plugin is vulnerable to a classic SQL injection through the log_table_filter parameter in all released versions up to 1.0.36. Because the value is concatenated directly into a query without escaping or prepared statements, an attacker who can log into the site with shop‑manager level or higher privileges can inject arbitrary SQL, allowing the retrieval of any database table or the execution of destructive statements. This weakness maps to CWE‑89 and the impact is the disclosure of sensitive data and potential integrity compromise.

Affected Systems

Any installation of the GoPay for WooCommerce WordPress plugin with a version of 1.0.36 or earlier is affected. The vulnerability applies to all environments where the plugin is active, regardless of host OS or database type, as long as a shop manager+ role exists in the WordPress installation.

Risk and Exploitability

The severity reflects a moderate CVSS score of 4.9, and the EPSS shows a probability below 1 %, indicating that it is unlikely to be observed in the wild. The vulnerability is not listed in CISA’s KEV catalog, further suggesting limited exploitation. Attackers must be authenticated to a role of shop manager or higher, which limits the threat to sites with weak role separation or compromised shop‑manager accounts. Because the attack requires elevated access, the overall risk remains moderate but should be mitigated promptly.

Generated by OpenCVE AI on September 19, 2026 at 23:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official plugin update to version 1.0.37 or later to resolve the injection flaw.
  • If an update cannot be applied immediately, restrict the shop manager+ role to a minimal set of trusted users and consider upgrading role permissions or temporarily disabling the log table feature.
  • Review database logs and server activity for anomalous queries, and audit user roles for any unauthorized or overly privileged accounts.

Generated by OpenCVE AI on September 19, 2026 at 23:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Gopayplugins
Gopayplugins gopay For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Gopayplugins
Gopayplugins gopay For Woocommerce
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title GoPay for WooCommerce <= 1.0.36 - Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Gopayplugins Gopay For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:22.276Z

Reserved: 2026-08-18T16:29:29.890Z

Link: CVE-2026-75959

cve-icon Vulnrichment

Updated: 2026-09-19T13:51:54.922Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:54.487

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-75959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:23Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')