Email Verification for WooCommerce vulnerable to SQL Injection
CVE-2024-49305
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 October 2024
What is CVE-2024-49305?
The vulnerability in WPFactory's Email Verification for WooCommerce plugin results from an improper neutralization of special elements used in SQL commands, leading to potential SQL Injection attacks. This flaw could allow attackers to manipulate the database queries responsible for email verification, compromising user data and potentially exposing sensitive information. Affected versions include those up to 2.8.10, making it crucial for users to apply the necessary security patches to mitigate risks associated with unauthorized database access.
Affected Version(s)
Email Verification for WooCommerce <= 2.8.10