Impact
The ELEX WooCommerce Request a Quote WordPress plugin before version 2.4.1 fails to sanitize the 'variation_id' parameter, permitting unauthenticated users to inject SQL into the database query. This flaw allows an attacker to read arbitrary data tables, potentially revealing sensitive customer information, order details, or authentication data. The vulnerability is a classic SQL injection, corresponding to CWE-89.
Affected Systems
Any WordPress site that runs the ELEX WooCommerce Request a Quote plugin at a version older than 2.4.1 is impacted. The plugin is a third‑party WooCommerce add‑on used on e‑commerce sites that allow quote requests, with no other vendors or product lines listed in the CNA data.
Risk and Exploitability
The flaw is exploitable by anyone with network access to the site, as authentication is not required. The CVSS score of 8.6 indicates a high severity. The EPSS score is 0.0019, and the vulnerability is not in the CISA KEV catalog, the capability to read arbitrary database content poses a high impact, especially on publicly exposed e‑commerce platforms. An attacker can send a crafted request to the quote form, supply a malicious 'variation_id', and obtain database responses that may surface confidential data.
OpenCVE Enrichment