PT-2025-9149 · Woocommerce · Multilevel Referral Affiliate Plugin For Woocommerce
Oncybersec
+1
·
Published
2025-03-01
·
Updated
2025-03-01
·
CVE-2024-13750
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Multilevel Referral Affiliate Plugin for WooCommerce versions up to 2.27
Description
The issue allows authenticated attackers with Subscriber-level access and above to inject SQL queries, potentially extracting sensitive information from the database. This is due to insufficient escaping on the
orderby parameter and lack of preparation on the existing SQL query.Recommendations
For versions up to 2.27, consider restricting access to the
orderby parameter in the affected API endpoint until a patch is available. As a temporary workaround, restrict database access to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multilevel Referral Affiliate Plugin For Woocommerce