Impact
The vulnerability arises from improper neutralization of special elements in SQL commands, allowing an attacker to inject arbitrary SQL through the Woocommerce Partial Shipment plugin. An exploited SQL injection can read or modify data in the WordPress database, potentially exposing customer information, altering orders, or compromising authentication credentials. The flaw is classified as CWE-89.
Affected Systems
Affected systems are installations of the WpExperts Hub Woocommerce Partial Shipment plugin for WordPress, any version from the initial release up through version 3.2. The official CNA marks the scope for all builds <=3.2; newer releases are not affected.
Risk and Exploitability
The CVSS base score of 8.5 indicates a high impact, while an EPSS score of <1% suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely send crafted requests to the plugin’s HTTP endpoints, so the risk remains if the plugin is active on a public site. Administrators should treat this as a high‑severity issue given the potential data exposure.
OpenCVE Enrichment
EUVD