CVE-2024-0399

CVE-2024-0399: WooCommerce Customers Manager < 29.7 - Subscriber+ SQL Injection

Vendor Unknown
Product WooCommerce Customers Manager
Published April 15, 2024
Last update March 27, 2025

CVSS base score

What the vulnerability does

01Description

The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.

Key dates

02Disclosure timeline

April 15, 2024 CVE published
March 27, 2025 Record updated