Summary
CVE-2026-56070 is a critical unauthenticated SQL injection vulnerability in ThemeHunk’s Advance Product Search plugin for WordPress and WooCommerce, affecting all versions up to and including 1.4.4. With a CVSS score of 9.3 (Critical), the flaw allows any remote, unauthenticated attacker to inject arbitrary SQL commands and extract sensitive data from the underlying WordPress database — no privileges or user interaction are required. The plugin has over 10,000 active installations on public-facing WooCommerce stores.
Technical details
- Root cause: Insufficient input sanitization in the plugin’s search handler (
thaps-function.php, lines 125–131), where user-supplied search terms were directly interpolated into a raw SQLLIKEclause without the use of parameterized prepared statements. - Trigger conditions: An attacker submits a crafted HTTP request to the plugin’s Ajax search endpoint. No authentication, session, or user interaction is required; the endpoint is publicly reachable on any site running the plugin.
- Attack vector: Remote, unauthenticated network request (Attack Vector: Network, Attack Complexity: Low, Privileges Required: None, User Interaction: None, Scope: Changed).
- Impact: Exploitation enables full read access to the WordPress database, including user credentials, customer personally identifiable information (PII), WooCommerce order records, and other sensitive data. A limited availability impact (Low) also exists, reflecting potential for minor service disruption.
Affected software
- ThemeHunk Advance Product Search (WordPress/WooCommerce plugin) — versions <= 1.4.4
Severity
- CVSS v3.1 Base Score: 9.3 (Critical)
- Vector string:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Mitigation and recommended actions
- Immediate: Update the plugin to version 1.4.5 or later. Version 1.4.5 resolves the SQL injection by replacing raw string interpolation with
$wpdb->prepare()parameterized queries. Version 1.4.6 (the current release as of the date of this advisory) includes additional security hardening. - If immediate patching is not feasible: Temporarily disable the Advance Product Search plugin until the update can be applied, or use a web application firewall (WAF) to block or restrict access to the WordPress Ajax endpoint (
/wp-admin/admin-ajax.php) from untrusted sources.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

