Impact
The WPMR Google Feed Manager for WooCommerce plugin contains a time‑based SQL Injection in the feed parameter. This is a CWE‑89 flaw. When an administrator or higher level user supplies an unescaped value, the plugin concatenates that value directly into the database query. As a result, an attacker can append additional SQL statements and read arbitrary data from the WordPress database. The vulnerability does not lead to code execution, but it does compromise the confidentiality and integrity of all data stored in the database.
Affected Systems
The issue affects the WordPress plugin WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping, owned by the author aukejomm. All releases up to and including version 2.23.7 are vulnerable; any version 2.23.7 or earlier is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. Because the flaw requires administrator‑level access, the attack vector is authenticated. This is a CWE‑89 SQL Injection vulnerability. There is no unprivileged remote exploitation path. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating limited publicly known exploitation. If an admin user inputs a specially crafted feed value through the plugin’s AJAX endpoint, the attacker can extract sensitive information from the database. The potential impact on confidential business data is significant, and the risk is elevated by the requirement for elevated privileges which can be more likely in shared hosting or compromised accounts.
OpenCVE Enrichment