PT-2021-19932 · Woocommerce · Woocommerce-Gutenberg-Products-Block

Josh

·

Published

2021-07-26

·

Updated

2021-10-28

·

CVE-2021-32789

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions woocommerce-gutenberg-products-block versions 2.5.0 through 2.5.15
Description An SQL injection issue affects WooCommerce sites running the WooCommerce Blocks feature plugin. This can be exploited via a carefully crafted URL against the "wc/store/products/collection-data?calculate attribute counts[][taxonomy]" endpoint, allowing the execution of a read-only SQL query.
Recommendations For versions 2.5.0 through 2.5.15, upgrade to version 2.5.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the "wc/store/products/collection-data?calculate attribute counts[][taxonomy]" endpoint until a patch is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32789
GHSA-6HQ4-W6WV-8WRP

Affected Products

Woocommerce-Gutenberg-Products-Block