CVE-2021-32789
HIGH EXPLOITED IN THE WILD NUCLEIWooCommerce Gutenberg Blocks <2.5.16 - SQL Injection
Title source: llmDescription
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.
Exploits (2)
Nuclei Templates (1)
WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection
HIGHby rootxharsh,iamnoooob,S1r1u5_,cookiehanhoan,madrobot
References (5)
Scores
CVSS v3
7.5
EPSS
0.9136
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2021-07-23
InTheWild.io
2021-07-15
CWE
CWE-89
Status
published
Products (1)
automattic/woocommerce_blocks
2.5.0 - 2.5.16
Published
Jul 26, 2021
Tracked Since
Feb 18, 2026