Impact
The vulnerability is a classic SQL Injection flaw (CWE-89) that allows an attacker to inject malicious SQL code into queries executed by the PDF Invoice Builder for WooCommerce plugin. The CVE description indicates that this flaw could enable extraction or manipulation of data stored in the database, but the exact impact on confidentiality or integrity is not explicitly detailed. Based on the nature of SQL injection, it is inferred that an attacker could potentially read, modify, or delete data, thereby compromising sensitive customer information or disrupting order processing.
Affected Systems
The affected product is add-ons.org PDF Invoice Builder for WooCommerce, also known as pdf-for-woocommerce. Any installation of the plugin up to and including version 5.3.8 is vulnerable; versions newer than 5.3.8 are not listed as affected.
Risk and Exploitability
The CVSS score of 7.6 classifies this as high severity. The EPSS score of less than 1% indicates a low but non-zero probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Attackers could potentially exploit the flaw via web-based interactions with the plugin, as the vulnerability involves an SQL command, but the specific vector is not described in the CVE data; it is inferred from typical patterns of SQL injection attacks.
OpenCVE Enrichment
EUVD