WordPress WooCommerce Payments Plugin <= 5.9.0 is vulnerable to SQL Injection
CVE-2023-35915
7.6HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 December 2023
What is CVE-2023-35915?
A vulnerability has been identified in WooPayments, a fully integrated payment solution developed by Automattic, which allows attackers to exploit an improper neutralization of special elements used in SQL commands. If left unaddressed, this flaw could enable unauthorized access to sensitive data or manipulation of the database. This issue affects all versions of WooPayments up to and including 5.9.0, underscoring the importance of promptly updating to the latest version to mitigate potential risks.
Affected Version(s)
WooPayments – Fully Integrated Solution Built and Supported by Woo <= 5.9.0