Impact
The vulnerability is a classic SQL injection flaw in the Recover abandoned cart for WooCommerce plugin that allows an attacker to inject arbitrary SQL statements into the database because special characters are not properly neutralized. An attacker can read, modify, or delete sensitive data stored in WooCommerce order or cart tables, thereby compromising customer information and store integrity. The flaw is classified as CWE-89 and the CVSS score of 9.3 indicates a critical impact.
Affected Systems
The affected product is the Recover abandoned cart for WooCommerce plugin by sonalsinha21, affecting all releases from the plugin's inception through version 2.5. The plugin is used on WordPress installations that include the WooCommerce e‑commerce extension.
Risk and Exploitability
Based on the description, the likely attack vector is through unauthenticated or low‑privilege HTTP requests to the plugin’s hooks or administrative URLs where user input is reflected directly in SQL queries. The CVSS score of 9.3 classifies this as a critical vulnerability, and the EPSS score of 58% indicates a high probability of active exploitation. The issue is not listed in CISA’s Known Exploited Vulnerabilities catalog, but the combination of severity and high EPSS suggests attackers could target vulnerable sites to retrieve or corrupt database contents.
OpenCVE Enrichment
EUVD