CVE-2026-32459 | flycart UpsellWP Plugin up to 2.2.4 on WordPress sql injection (EUVD-2026-12017)
A vulnerability was found in flycart UpsellWP Plugin up to 2.2.4 on WordPress. It has been rated as critical. This impacts an unknown function. Performing a manipulation results in sql injection.
This vulnerability is identified as CVE-2026-32459. The attack can be initiated remotely. There is not any exploit available.