Weekly roundup
Open-source business platforms, week 36 of 2026: WooCommerce SQL injection and Dolibarr access control
Open-source business platforms, week 36 of 2026: two CVEs, one high and one medium. WooCommerce before 11.0 has a high-severity SQL injection; Dolibarr has a medium-severity access-control weakness fixed in 23.0.4. Neither is in CISA KEV. Update WooCommerce first.
The release at a glance
The release for open-source business platforms in week 36 of 2026, covering 31 August to 6 September, contains two CVEs in scope: one high-severity vulnerability in WooCommerce and one medium-severity vulnerability in Dolibarr. The WooCommerce issue is a blind SQL injection; the Dolibarr issue is an improper access-control weakness in the legacy file manager. Neither CVE is listed in CISA KEV, and neither is marked as exploited. The WooCommerce fix is WooCommerce 11.0. The CVE record for Dolibarr states that upgrading to version 23.0.4 resolves the issue, and it notes that an exploit has been made available to the public. A public exploit is a reason to patch promptly, but it is not the same as active exploitation. Both vulnerabilities have fixes available, so there is no need to wait for a follow-on release. For prioritisation, the severity split is one high and one medium, and the product split is one WooCommerce and one Dolibarr.
What matters most
The two flaws sit in separate products.
WooCommerce: CVE-2026-57777 is a blind SQL injection vulnerability affecting WooCommerce before 11.0. It is rated 7.6 high under CVSS 3.1, with a network attack vector, low attack complexity, high privileges required, no user interaction, and changed scope. The vector shows high confidentiality impact, no integrity impact, and low availability impact, so the primary concern is unauthorised data access after an attacker holds a high-privilege account. Update to WooCommerce 11.0.
Dolibarr: CVE-2026-85401 is an improper access-control weakness in the legacy file manager component, affecting htdocs/core/filemanagerdol/connectors/php/config.inc.php. It is rated 5.3 medium under CVSS 4.0, can be launched remotely with low privileges, and has proof-of-concept exploit maturity. The CVE record lists affected versions including 21.0.0 through 21.0.4 and 22.0.0 through 22.0.2; the advisory describes affected versions up to 21.0.4/22.0.5/23.0.3. Upgrade to Dolibarr 23.0.4.
Patch in this order
- Update WooCommerce to 11.0 first. It is the only high-severity flaw in this release and affects the WordPress WooCommerce plugin. The high privileges requirement lowers the immediate attack surface, but the network vector and high confidentiality impact make it the priority.
- Upgrade Dolibarr to 23.0.4 next. The flaw is medium severity, but the public exploit availability means it should follow promptly in patch cycles, especially for instances that expose the legacy file manager.
- Check that the updates reach all affected instances, particularly those reachable over the network. Neither flaw is in CISA KEV, so no CISA-mandated due date applies.
Beyond the patch
A two-CVE week across separate products is manageable if you know what you run and how quickly suppliers fix it. Supply Chain Defense & Third-Party Risk tracks which vendors' software you run and how fast they fix it, so a week like this becomes a simple comparison of your inventory against the vendor release. Implementation & Assessment Services is where injection, deserialisation and authentication flaws are found before a release. For teams working to NIS2 or DORA, recording this update provides clear evidence of supply-chain patch management. That turns decisions like this into a short, evidence-led conversation.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-57777 | WooCommerce | High 7.6 | |
| CVE-2026-85401 | Dolibarr | Medium 5.3 |
References
Vendor advisory
Patch and release notes
Other
- patchstack.com/database/wordpress/plugin/woocommerce/vulnerability/wordpress-woocommerc…
- VDB-398543 | Dolibarr Legacy File Manager config.inc.php access control
- VDB-398543 | CTI Indicators (IOB, IOC, TTP, IOA)
- CVE-2026-85401 | CVE Analysis and Report
- Submit #894869 | Dolibarr -server 21.0/22.0 BROKEN ACCESS CONTROL (STILL UNPATCHED) in …
- github.com/Dolibarr/dolibarr/