Impact
The CardGate Payments for WooCommerce plugin contains an improper neutralization of special elements used in an SQL command, which allows a blind SQL injection. The flaw permits an attacker to craft SQL payloads that are executed by the backend database, potentially enabling extraction of sensitive data or unauthorized modification of the database. The weakness is a classic SQL injection (CWE‑89) involving unsanitized user input passed directly to a database query.
Affected Systems
Affected vendor: CardGate. Product: CardGate Payments for WooCommerce plugin. Versions ranging from the earliest available releases up to and including version 3.2.1 are vulnerable. Any WordPress site that has installed CardGate Payments for WooCommerce 3.2.1 or earlier is at risk.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. The EPSS score is less than 1%, reflecting a low current probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is through the plugin’s public-facing or administrative interfaces where unvalidated input is processed, such as payment forms or order management pages. Even though exploitation probability is low, the high consequence of a potential data breach mandates prompt remediation.
OpenCVE Enrichment
EUVD