Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 9.9%
from disclosure to weapon
Published on NVDMay 9
VulnCheck+1400d
exploitation probability
9.9%top 5% of all CVEs
observed exploitation
yesVulnCheck
The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection