Email Verification for WooCommerce vulnerable to SQL Injection
CVE-2024-49305
9.3CRITICAL
Key Information:
- Vendor
- WPfactory
- Status
- Email Verification For WooCommerce
- Vendor
- CVE Published:
- 17 October 2024
Summary
The vulnerability in WPFactory's Email Verification for WooCommerce plugin results from an improper neutralization of special elements used in SQL commands, leading to potential SQL Injection attacks. This flaw could allow attackers to manipulate the database queries responsible for email verification, compromising user data and potentially exposing sensitive information. Affected versions include those up to 2.8.10, making it crucial for users to apply the necessary security patches to mitigate risks associated with unauthorized database access.
Affected Version(s)
Email Verification for WooCommerce <= 2.8.10
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
shaman0x01 (Patchstack Alliance)