PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-42383 YITH CVE debrief

CVE-2026-42383 is a high-severity blind SQL injection issue in YITH WooCommerce Product Add-Ons, affecting versions through 4.29.0. The supplied CVSS vector indicates network exposure with high privileges required and no user interaction, with confidentiality impact rated high.

Vendor
YITH
Product
YITH WooCommerce Product Add-Ons
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-20
Original CVE updated
2026-07-24
Advisory published
2026-05-20
Advisory updated
2026-07-24

Who should care

WordPress site owners using YITH WooCommerce Product Add-Ons, WordPress administrators, managed hosting teams, and incident responders responsible for plugin risk management.

Technical summary

The NVD record describes an improper neutralization of special elements used in an SQL command (CWE-89) that allows blind SQL injection in YITH WooCommerce Product Add-Ons through version 4.29.0. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L, indicating a remotely reachable issue that requires high privileges and can have significant confidentiality impact. NVD lists the vulnerability status as Deferred and cites a Patchstack reference for the issue.

Defensive priority

High

Recommended defensive actions

  • Confirm whether YITH WooCommerce Product Add-Ons is installed and whether any instance is at version 4.29.0 or earlier.
  • Apply the first vendor-fixed version as soon as it is available, or temporarily disable the plugin if patching cannot be completed promptly.
  • Limit access to WordPress administrative and plugin-management functions to the smallest practical set of privileged users.
  • Review server, application, and database logs for unusual repeated query patterns or other signs consistent with blind SQL injection probing.
  • Follow the Patchstack and NVD references for remediation guidance and update tracking.

Evidence notes

The affected product name and version range come from the CVE description supplied with the record. The NVD source item shows the record was published and modified on 2026-05-20, includes CWE-89, and lists vulnStatus as Deferred. The only reference in the supplied NVD metadata points to a Patchstack advisory page. No CISA KEV dates were supplied in the prompt.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-42383 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-42383

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-42383 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42383

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.