« Back to list

Woocommerce Lottery

Woocommerce Lottery: vulnerabilities and CVEs

Woocommerce Lottery has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-32580High (7.5)0.31%—Oct 6, 2026
Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.
CVE-2026-18884High (7.5)0.32%—Aug 26, 2026
The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System2
  2. T1190 Exploit Public-Facing Application2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.