Impact
Productive Minds' Productive Commerce plugin for WordPress versions up to 1.1.40 contains an SQL injection flaw. The plugin fails to properly neutralise special characters used in SQL commands, allowing an attacker to inject arbitrary SQL. This can result in unauthorised reading, modification or deletion of database records, potentially leading further to data exfiltration, credential compromise, or escalation of privileges within the WordPress site. The vulnerability is classified as CWE‑89.
Affected Systems
WordPress sites that have installed Productive Minds' Productive Commerce plugin version 1.1.40 or older are affected. The issue applies to all operating systems where the plugin is deployed, as the flaw resides in the PHP code rather than the underlying platform.
Risk and Exploitability
With a CVSS score of 9.3 the risk is critical. The EPSS score is under 1%, indicating that publicly documented exploitation has not yet been observed, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via web traffic – a malicious actor could send crafted requests to the vulnerable plugin’s endpoints to trigger SQL injection. Despite the low exploitation probability, the high severity warrants immediate remediation.
OpenCVE Enrichment
EUVD