PatchSiren cyber security CVE debrief
CVE-2026-42383 YITH CVE debrief
CVE-2026-42383 is a high-severity blind SQL injection issue in YITH WooCommerce Product Add-Ons, affecting versions through 4.29.0. The supplied CVSS vector indicates network exposure with high privileges required and no user interaction, with confidentiality impact rated high.
- Vendor
- YITH
- Product
- YITH WooCommerce Product Add-Ons
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-05-20
Who should care
WordPress site owners using YITH WooCommerce Product Add-Ons, WordPress administrators, managed hosting teams, and incident responders responsible for plugin risk management.
Technical summary
The NVD record describes an improper neutralization of special elements used in an SQL command (CWE-89) that allows blind SQL injection in YITH WooCommerce Product Add-Ons through version 4.29.0. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L, indicating a remotely reachable issue that requires high privileges and can have significant confidentiality impact. NVD lists the vulnerability status as Deferred and cites a Patchstack reference for the issue.
Defensive priority
High
Recommended defensive actions
- Confirm whether YITH WooCommerce Product Add-Ons is installed and whether any instance is at version 4.29.0 or earlier.
- Apply the first vendor-fixed version as soon as it is available, or temporarily disable the plugin if patching cannot be completed promptly.
- Limit access to WordPress administrative and plugin-management functions to the smallest practical set of privileged users.
- Review server, application, and database logs for unusual repeated query patterns or other signs consistent with blind SQL injection probing.
- Follow the Patchstack and NVD references for remediation guidance and update tracking.
Evidence notes
The affected product name and version range come from the CVE description supplied with the record. The NVD source item shows the record was published and modified on 2026-05-20, includes CWE-89, and lists vulnStatus as Deferred. The only reference in the supplied NVD metadata points to a Patchstack advisory page. No CISA KEV dates were supplied in the prompt.
Official resources
-
CVE-2026-42383 CVE record
CVE.org
-
CVE-2026-42383 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
Publicly disclosed in the supplied NVD record on 2026-05-20, with the same record modified later that day. The NVD metadata marks the issue as Deferred and cites a Patchstack reference; no KEV entry is listed in the supplied timeline.