PT-2022-9513 · WordPress · Rearrange Woocommerce Products

Krzysztof Zając

·

Published

2022-02-07

·

Updated

2022-10-24

·

CVE-2021-24928

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rearrange Woocommerce Products WordPress plugin versions prior to 3.0.8
Description The issue is related to improper access controls in the save all order AJAX action and lack of validation and escaping when inserting user data into SQL statements, leading to an SQL injection. This allows any authenticated user to modify arbitrary post content, potentially with an XSS payload, and exfiltrate data by copying it to another post.
Recommendations For versions prior to 3.0.8, update to version 3.0.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the save all order AJAX action to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-24928

Affected Products

Rearrange Woocommerce Products