The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-08T20:33:40.528Z
Reserved: 2024-01-10T15:10:32.475Z
Link: CVE-2024-0399

Updated: 2024-08-01T18:04:49.575Z

Status : Awaiting Analysis
Published: 2024-04-15T05:15:14.627
Modified: 2024-11-21T08:46:29.970
Link: CVE-2024-0399

No data.