Impact
The vulnerability is an SQL injection flaw caused by improper neutralization of special elements in an SQL command in the WooCommerce Point Of Sale (POS) WordPress plugin. Based on the description, this flaw allows an attacker to inject malicious SQL code, which can lead to unauthorized data extraction, database alteration, or escalation of privileges depending on the underlying database permissions.
Affected Systems
The flaw affects all releases of the WooCommerce Point Of Sale (POS) plugin by infosoftplugin up to and including version 1.4. All WordPress sites installing this plugin are potentially exposed unless a newer, patched release is used.
Risk and Exploitability
The CVSS score of 8.5 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a low probability of current exploitation in the wild, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves sending crafted HTTP requests containing malicious input to the plugin, assuming the site is reachable and the database is accessible via the plugin.
OpenCVE Enrichment
EUVD