PT-2024-15526 · WordPress · Woocommerce Customers Manager

Ivan Spiridonov

+1

·

Published

2024-04-14

·

Updated

2025-04-16

·

CVE-2024-0399

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce Customers Manager WordPress plugin versions prior to 29.7
Description The issue is related to an SQL injection that occurs because a parameter is not properly sanitised and escaped before being used in a SQL statement. This can be exploited by users with a Subscriber+ role.
Recommendations For versions prior to 29.7, update the WooCommerce Customers Manager WordPress plugin to version 29.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality for users with the Subscriber+ role until the update is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-0399

Affected Products

Woocommerce Customers Manager