Showing 1 vulnerability on this page for woocommerce-gutenberg-products-block

Signals CISA KEV Ransomware Nuclei
WooCommerce vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Arbitrary SQL (SQL injection) possible via the Store API component.

woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this pac

CWE-89Jul 26, 20211 related artifact
CVSS7.5v3.1EPSS17.2%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX