Impact
The FlexStock stock‑sync‑with‑google‑sheet‑for‑woocommerce plugin contains an improper neutralization of special elements in an SQL command that allows blind SQL injection. Based on the description, it is inferred that an attacker can craft HTTP requests that inject malicious SQL into database queries, potentially retrieving sensitive information such as user credentials, order data, or, if database privileges are high enough, modifying or deleting data. The vulnerability is a classic SQL injection flaw (CWE‑89).
Affected Systems
The flaw affects the WPPOOL FlexStock plugin for WordPress in all versions from the initial release up to and including 3.13.1. Any site running this plugin within that version range is susceptible.
Risk and Exploitability
The CVSS score of 7.6 categorizes the weakness as high severity, while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack can be executed remotely through the plugin’s HTTP interface, likely without the need for authentication, by sending specially crafted requests to trigger the blind SQL injection.
OpenCVE Enrichment
EUVD