PT-2024-15526 · WordPress · Woocommerce Customers Manager
Ivan Spiridonov
+1
·
Published
2024-04-14
·
Updated
2025-04-16
·
CVE-2024-0399
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WooCommerce Customers Manager WordPress plugin versions prior to 29.7
Description
The issue is related to an SQL injection that occurs because a parameter is not properly sanitised and escaped before being used in a SQL statement. This can be exploited by users with a Subscriber+ role.
Recommendations
For versions prior to 29.7, update the WooCommerce Customers Manager WordPress plugin to version 29.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality for users with the Subscriber+ role until the update is applied.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woocommerce Customers Manager