Impact
The ELEX WooCommerce Bulk Edit Products, Prices & Attributes plugin contains an SQL Injection flaw in the 'attribute_value_filter' parameter. Versions through and including 1.4.9 fail to properly escape input and do not prepare the SQL statement, permitting authenticated users with Subscriber or higher access to inject and append arbitrary SQL queries. This capability enables attackers to read confidential information from the WordPress database, potentially including customer data, product details, and administrative credentials.
Affected Systems
The vulnerability affects the "ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic)" plugin distributed by Elextensions. All releases up to and including version 1.4.9 are impacted; newer releases are not known to contain the flaw.
Risk and Exploitability
With a CVSS score of 6.5 the risk is considered moderate. The EPSS score of less than 1 % indicates a very low probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. The attack requires authenticated access, so users must already have at least Subscriber privileges. If successfully exploited, an attacker could retrieve sensitive database contents but would not gain binary code execution. The overall threat is primarily data theft with limited impact on availability or integrity of the system.
OpenCVE Enrichment
EUVD