Impact
The Perfect Brands for WooCommerce plugin contains a time‑based SQL injection vulnerability in the brands attribute of the products shortcode. This flaw allows authenticated users with Contributor or higher privileges to inject additional SQL statements, enabling extraction of sensitive information from the WordPress database.
Affected Systems
The vulnerability affects all installations of the Perfect Brands for WooCommerce plugin from its earliest release through version 3.6.2. Users employing any of these versions on a WordPress site are potentially impacted and should verify their plugin version.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, with an EPSS score of less than 1% suggesting a very low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate to the site and possess at least Contributor privileges; once logged in, they can use the shortcode to inject malicious SQL. The impact is data disclosure, as attackers can read sensitive database contents.
OpenCVE Enrichment