SQL Injection Vulnerability in Cost Of Goods
CVE-2024-53783

7.6HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
30 November 2024

Summary

An SQL Injection vulnerability exists within the Anzia Ni WooCommerce Cost Of Goods plugin, allowing attackers to execute arbitrary SQL commands through improperly sanitized user inputs. This security flaw affects all versions of the plugin from unspecified to version 3.2.8, potentially compromising the integrity and security of the databases associated with the affected sites. Administrators using this plugin should promptly assess the security of their installations to prevent exploitation.

Affected Version(s)

Ni WooCommerce Cost Of Goods <= 3.2.8

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hakiduck (Patchstack Alliance)
.