What the vulnerability does
01Description
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
Explanation of Vulnerability in Simple Terms
MailChimp For WooCommerce versions before 6.2 contain a SQL injection vulnerability in database queries. An attacker with high-level site privileges can craft malicious input to read or modify database contents. The vulnerability affects the broader site scope and may expose sensitive customer or order data stored in the database.
What an attacker can do
Read or modify database records by injecting SQL commands through the plugin.
Potential impact on your site
Customer data, orders, and other database records could be exposed or altered by a compromised admin account.
Conditions required to exploit
Attacker must have high-level site privileges (administrator or equivalent role).
Key dates
External resources
Related vulnerabilities