What the vulnerability does
01Description
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Explanation of Vulnerability in Simple Terms
Suggestion Engine for WooCommerce versions up to 2.0.11 contain a SQL injection vulnerability in a component requiring low-level authentication. An attacker with a user account can craft malicious input to execute arbitrary SQL queries, potentially reading sensitive data from the database. The vulnerability affects multiple users and may impact site availability.
What an attacker can do
Read sensitive data from the site database and cause service disruption.
Potential impact on your site
Customer data, product information, and other database records may be exposed or deleted.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities