What the vulnerability does
01Description
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
What the vulnerability does
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.
Explanation of Vulnerability in Simple Terms
The Homepage Product Organizer for WooCommerce plugin version 1.1 and earlier contains a SQL injection vulnerability in its database queries. An authenticated user with low privileges can inject malicious SQL code through plugin parameters, potentially reading sensitive data from the WordPress database and modifying store content. The vulnerability affects multiple database operations and has a high CVSS score of 9.1.
What an attacker can do
Read sensitive data from the WordPress database and modify store content via SQL injection.
Potential impact on your site
Store data, customer information, and product details could be exposed or altered by any low-privilege user.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities