CVE-2026-82304
Music Store โ WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
| Vendor | unknown |
| Product | music store |
| Published | Sep 5, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown music store
Be the first to know when new high vulnerabilities affecting unknown music store are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Music Store
1.0.245 < 1.4.5
References
Credits
nobody WPScan