Email Verification for WooCommerce vulnerable to SQL Injection
CVE-2024-49305

9.3CRITICAL

Key Information:

Vendor
WPfactory
Status
Email Verification For WooCommerce
Vendor
CVE Published:
17 October 2024

Summary

The vulnerability in WPFactory's Email Verification for WooCommerce plugin results from an improper neutralization of special elements used in SQL commands, leading to potential SQL Injection attacks. This flaw could allow attackers to manipulate the database queries responsible for email verification, compromising user data and potentially exposing sensitive information. Affected versions include those up to 2.8.10, making it crucial for users to apply the necessary security patches to mitigate risks associated with unauthorized database access.

Affected Version(s)

Email Verification for WooCommerce <= 2.8.10

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

shaman0x01 (Patchstack Alliance)
.