PatchSiren cyber security CVE debrief
CVE-2026-42383 YITH CVE debrief
CVE-2026-42383 is a high-severity blind SQL injection issue in YITH WooCommerce Product Add-Ons, affecting versions through 4.29.0. The supplied CVSS vector indicates network exposure with high privileges required and no user interaction, with confidentiality impact rated high.
- Vendor
- YITH
- Product
- YITH WooCommerce Product Add-Ons
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-24
Who should care
WordPress site owners using YITH WooCommerce Product Add-Ons, WordPress administrators, managed hosting teams, and incident responders responsible for plugin risk management.
Technical summary
The NVD record describes an improper neutralization of special elements used in an SQL command (CWE-89) that allows blind SQL injection in YITH WooCommerce Product Add-Ons through version 4.29.0. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L, indicating a remotely reachable issue that requires high privileges and can have significant confidentiality impact. NVD lists the vulnerability status as Deferred and cites a Patchstack reference for the issue.
Defensive priority
High
Recommended defensive actions
- Confirm whether YITH WooCommerce Product Add-Ons is installed and whether any instance is at version 4.29.0 or earlier.
- Apply the first vendor-fixed version as soon as it is available, or temporarily disable the plugin if patching cannot be completed promptly.
- Limit access to WordPress administrative and plugin-management functions to the smallest practical set of privileged users.
- Review server, application, and database logs for unusual repeated query patterns or other signs consistent with blind SQL injection probing.
- Follow the Patchstack and NVD references for remediation guidance and update tracking.
Evidence notes
The affected product name and version range come from the CVE description supplied with the record. The NVD source item shows the record was published and modified on 2026-05-20, includes CWE-89, and lists vulnStatus as Deferred. The only reference in the supplied NVD metadata points to a Patchstack advisory page. No CISA KEV dates were supplied in the prompt.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42383 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42383
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42383 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42383
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.