PT-2021-19932 · Woocommerce · Woocommerce-Gutenberg-Products-Block
Josh
·
Published
2021-07-26
·
Updated
2021-10-28
·
CVE-2021-32789
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
woocommerce-gutenberg-products-block versions 2.5.0 through 2.5.15
Description
An SQL injection issue affects WooCommerce sites running the WooCommerce Blocks feature plugin. This can be exploited via a carefully crafted URL against the "wc/store/products/collection-data?calculate attribute counts[][taxonomy]" endpoint, allowing the execution of a read-only SQL query.
Recommendations
For versions 2.5.0 through 2.5.15, upgrade to version 2.5.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the "wc/store/products/collection-data?calculate attribute counts[][taxonomy]" endpoint until a patch is applied.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woocommerce-Gutenberg-Products-Block