Skip to content
SQL Injection Vulnerabilities Disclosed in WooCommerce and Captivate Sync

SQL Injection Vulnerabilities Disclosed in WooCommerce and Captivate Sync

First seen 2 Oct 2026, 13:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 13:09 UTC

Two SQL Injection vulnerabilities, CVE-2026-102379 and CVE-2026-62060, were disclosed on October 1, 2026. CVE-2026-102379 affects VillaTheme BuildKit for WooCommerce, allowing Blind SQL Injection, with a CVSS score of 8.5. CVE-2026-62060 impacts Captivate Sync, also permitting Blind SQL Injection, with a CVSS score of 7.6. Both vulnerabilities are not confirmed to be actively exploited. The affected versions for BuildKit range from n/a to 1.0.28, while Captivate Sync is affected from n/a to 3.3.2. Security professionals are advised to check their systems for these vulnerabilities using available tools.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-01-29
CVE-2026-1340 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
CVE-2026-102379 published
VillaTheme BuildKit for WooCommerce was found to have a Blind SQL Injection vulnerability.
Ismalicious
2026-10-01
CVE-2026-62060 published
Captivate Sync was identified with a Blind SQL Injection vulnerability.
Ismalicious

More articles in this cluster (2)

Following this threat?

Track CVE-2026-102379 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of BuildKit are affected?
BuildKit versions from n/a to 1.0.28 are affected by CVE-2026-102379.
What versions of Captivate Sync are affected?
Captivate Sync versions from n/a to 3.3.2 are affected by CVE-2026-62060.
Are there any known exploits for these vulnerabilities?
No active exploitation of either CVE-2026-102379 or CVE-2026-62060 has been confirmed.