Impact
This vulnerability arises from improper handling of special characters in an SQL command within the Perfect Brands for WooCommerce plugin. The flaw allows an attacker to inject arbitrary SQL statements, leading to data disclosure, modification, or potential deletion of critical site data. The weakness corresponds to CWE‑89 and is reflected in the high CVSS score of 8.5, indicating significant confidentiality and integrity risks.
Affected Systems
The flaw affects the quadlayers Perfect Brands for WooCommerce plugin for WordPress versions up to and including 3.6.2. Users running any of these versions on their WordPress sites are susceptible unless the plugin has been upgraded beyond the stated threshold.
Risk and Exploitability
The EPSS score is less than 1%, suggesting that widespread exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could leverage the plugin’s exposed input points over the network to execute SQL commands, especially if the site’s data sources are accessible. Given the high CVSS value, the risk to affected installations remains significant.
OpenCVE Enrichment
EUVD