CVE-2024-12109

CVE-2024-12109: Product Labels For Woocommerce < 1.5.9 - Admin+ SQLi

Vendor Unknown
Product Product Labels For Woocommerce (Sale Badges)
Published March 25, 2025
Last update March 25, 2025

CVSS base score

What the vulnerability does

01Description

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

Key dates

02Disclosure timeline

March 25, 2025 CVE published
March 25, 2025 Record updated