Impact
The Advance Product Search‑Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to a generic SQL injection through the 's' and 'match' parameters in all releases up through 1.4.4. Insufficient escaping of user‑supplied data and lack of prepared statements allow an attacker to append malicious SQL code to existing queries, enabling the extraction of sensitive database contents without any authentication.
Affected Systems
Any WordPress site that has the themehunk Advance Product Search‑Voice & Ajax Search for WooCommerce plugin installed at version 1.4.4 or earlier is affected. This includes all WordPress installations that have not updated the plugin beyond that version.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is classified as high. The EPSS score of less than 1% indicates that the probability of exploitation is currently low but not zero, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via standard HTTP requests that include the 's' or 'match' query parameters. An unauthenticated attacker can craft requests to inject and execute arbitrary SQL, potentially compromising the entire database.
OpenCVE Enrichment