---
id: CVE-2026-42714
title: >-
  Improper Neutralization of Special Elements used in an SQL Command ('SQL
  Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce)
  pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly
  (para Woocomme…
summary: >-
  Improper Neutralization of Special Elements used in an SQL Command ('SQL
  Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce)
  pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly
  (para Woocomme…
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'
cwe:
  - CWE-89
vendor: Piggly Dev
product: pix-por-piggly
affected:
  - pix-por-piggly <= 2.1.2
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:24:53.103'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42714'
references:
  - url: >-
      https://patchstack.com/database/wordpress/plugin/pix-por-piggly/vulnerability/wordpress-pix-por-piggly-para-woocommerce-plugin-2-1-2-sql-injection-vulnerability?_s_id=cve
    label: audit@patchstack.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T11:26:47.655Z'
---

## Overview

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly (para Woocommerce): from n/a through 2.1.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
