What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.50.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.50.
Explanation of Vulnerability in Simple Terms
AutomateWoo versions up to 4.9.50 contain a SQL injection vulnerability in database query construction. An authenticated user with low privileges can craft malicious input to execute arbitrary SQL commands, potentially reading sensitive data from the WordPress database. The vulnerability affects the scope beyond the vulnerable component itself.
What an attacker can do
Read sensitive data from the WordPress database by injecting SQL commands through the vulnerable input.
Potential impact on your site
Customer data, order information, and other database contents could be exposed to authenticated users with minimal privileges.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site (e.g., subscriber or customer role).
Key dates
External resources
Related vulnerabilities