nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-0399 CVE-2024-0399
HIGH
WooCommerce Customers Manager < 29.7 - Subscriber+ SQL Injection
Record summary
CVE-2024-0399 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
Description source: CVE List
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WooCommerce Customers ManagerDefault status: unaffected | CVE List | Before 29.7 | affected |
woocommerce_customers_managerBrowse woocommerce / woocommerce_customers_managerDefault status: unaffected | CVE List | Before 29.7 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBWooCommerce Customers Manager 29.4 - Post-Authenticated SQL InjectionExploitDB exploitby Ivan SpiridonovNot analyzed1 file
Repository PoCs
GitHubxbz0n/CVE-2024-0399Repository PoCby xbz0nStars: 1Not analyzed1 file
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/1550e30c-bf80-48e0-bc51-67d29ebe7272