Impact
Techspawn WhatsCart for WooCommerce is vulnerable to an SQL injection flaw stemming from improper neutralization of special elements in SQL commands (CWE-89). Unauthenticated or authenticated users could supply malicious input that is concatenated directly into database queries, allowing them to read, modify, or delete arbitrary data stored in the WordPress database. The consequences involve loss of confidentiality, integrity, and potentially the availability of user and order information.
Affected Systems
WordPress sites that have installed the Techspawn WhatsCart plugin version 1.1.0 or earlier are affected. This includes any deployment of the plugin with the product name "WhatsCart – Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce". No specific WordPress core or WooCommerce version constraints are listed.
Risk and Exploitability
Based on the description, it is inferred that attackers must supply malicious input to one of the plugin‑provided interfaces – for example, the chat or order‑notification endpoint – because the flaw arises from improper neutralization of special characters in SQL commands that are concatenated directly into queries. The CVSS score of 9.3 shows critical severity, while the EPSS score of less than 1% indicates that widespread exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. If exploited, the attacker could execute arbitrary SQL statements, enabling full read/write access to the WordPress database and potentially leading to data theft or further site compromise.
OpenCVE Enrichment
EUVD