CVE-2026-12753: Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter
The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Security readout for executives and security teams
Plain-English summary
This affects a WooCommerce search plugin. Public visitors may be able to manipulate search inputs so the WordPress database returns sensitive data. The issue is high severity because no login or user interaction is required, but the provided sources do not show confirmed active exploitation.
Executive priority
Treat this as urgent for affected WooCommerce stores because it can expose sensitive database information without authentication. Prioritize inventory, temporary removal if needed, and vendor-guided patching.
Technical view
CVE-2026-12753 is an unauthenticated SQL injection in themehunk Advance Product Search- Voice & Ajax Search for WooCommerce through 1.4.4. The weakness is insufficient escaping and query preparation for the `s` and `match` parameters, mapped to CWE-89 with CVSS 3.1 score 7.5.
Likely exposure
Exposure is limited to WordPress/WooCommerce sites using this specific plugin at versions up to and including 1.4.4. Internet-facing store search functionality increases practical risk because the vulnerable inputs are unauthenticated.
Exploitation context
The CVE states unauthenticated attackers can append SQL into existing queries to extract sensitive database information. KEV is false in the bundle, and no cited source confirms exploitation in the wild.
Researcher notes
The bundle includes vulnerable code line references and a WordPress Trac changeset, but does not provide a clear fixed version. Avoid assuming remediation beyond vendor guidance. Affected metadata appears incomplete, while title and description state through 1.4.4.
Mitigation direction
Inventory WordPress sites for the affected plugin and version.
Check Wordfence, WordPress plugin, and vendor guidance for a fixed release.
Update to a fixed version when vendor guidance identifies one.
Disable or remove the plugin if no fixed version is available.
Review WAF and application logs for suspicious search parameter activity.
Validation and detection
Confirm whether `th-advance-product-search` is installed on each WordPress site.
Record installed plugin versions and flag versions up to 1.4.4.
Review public search endpoints accepting `s` or `match` parameters.
Check database and web logs for unusual search requests or errors.
Track vendor changelog or WordPress Trac updates for remediation status.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-89: Database access and collection lookup
Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.