Ni WooCommerce Custom Order Status < 1.9.7 - Subscriber+ SQL Injection
CVE-2021-24846

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 December 2021

Summary

The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber

Affected Version(s)

Ni WooCommerce Custom Order Status 1.9.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JrXnm
.