CRITICAL 9.3 CVE-2026-32557 Published 6 Oct 2026

WooCommerce Appointments Plugin SQL Injection Vulnerability

Worried this affects your website?

An unauthenticated SQL Injection vulnerability has been found in WooCommerce Appointments.

Affected versions include WooCommerce Appointments 5.3.2 and earlier.

  • Attackers can exploit this flaw without authentication.
  • The vulnerability allows SQL injection through the plugin.

Reference: CVE-2026-32557 on NVD

← Back to Security News