Skip to main content
QUIETLYTIC
Vulnerability

WooCommerce Lottery SQL Injection (CVE-2026-18884)

CVE-2026-18884 is a CVSS 7.5 unauthenticated SQL injection in the WooCommerce Lottery WordPress plugin, per VulnCheck alone.

CVE-2026-18884
Threat Level
HIGH
CVSS
7.5
Status
Active Exploitation
Confidence
Medium
Affected Products
WooCommerce Lottery (up to 2.2.9)

CVE-2026-18884 carries a CVSS 3.1 base score of 7.5 against the WooCommerce Lottery plugin for WordPress. NVD classifies it as CWE-89 (SQL Injection) and states the flaw affects all versions up to and including 2.2.9. VulnCheck’s KEV feed reports the CVE as exploited, dated September 10, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-18884 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description states the plugin is vulnerable to time-based SQL injection through its orderby and order GET parameters, caused by insufficient escaping of the user-supplied values and a lack of proper query preparation on the affected SQL statement. NVD states this makes it possible for unauthenticated attackers to append additional SQL queries onto an existing query, which can be used to extract sensitive information from the underlying database.

Evidence and confidence

  • Medium confidence — the CVSS 7.5 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the CWE-89 classification, the fixed-version boundary (2.2.9), and the described mechanism all trace to NVD alone in our current ingestion, corroborated by Wordfence’s threat intelligence entry for this CVE. The exploitation report traces to VulnCheck KEV alone.
  • Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00414, a 35.2nd percentile score as of our ingestion.

No field is in conflict between our two sources.

Why this matters

Time-based SQL injection is a blind technique — the attacker doesn’t see query output directly, but infers database contents by measuring how long the server takes to respond to crafted, conditional queries — which means this class of flaw can go undetected far longer than an SQL injection that returns data directly in a response, since there’s no visible error message or altered page content to flag it. WooCommerce sites process order, customer, and payment-adjacent data, making an unauthenticated route to extract database contents a serious risk regardless of how subtle the extraction technique is; any site running a pre-2.2.9 version of this plugin should treat this as a priority patch.

Frequently Asked Questions

What is CVE-2026-18884? A CVSS 7.5 time-based SQL injection vulnerability (CWE-89) in the WooCommerce Lottery WordPress plugin, affecting versions up to and including 2.2.9, exploitable via the orderby and order GET parameters.

Is CVE-2026-18884 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 10, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by unauthenticated attackers.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Is a fixed version available? Our source data does not carry a specific fixed-version number beyond NVD’s statement that versions “up to, and including, 2.2.9” are affected. Consult the plugin vendor directly for the current patched release.


Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-18884, corroborated by Wordfence’s threat intelligence entry. Exploitation status and the September 10, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools