Impact
This flaw is a blind SQL injection vulnerability in the Product Rearrange for WooCommerce plugin that allows an attacker to read sensitive data or alter database contents. The vulnerability stems from improper neutralization of special elements within an SQL command, a weakness classified as CWE‑89.
Affected Systems
The mistake is present in all releases of Devteam HaywoodTech Product Rearrange for WooCommerce up through version 1.2.2. Site owners who have not upgraded past this point are subject to the risk.
Risk and Exploitability
The CVSS base score is 9.3, indicating critical severity, yet the EPSS score is less than 1 % and the flaw is not listed in the CISA KEV catalog, which suggests that exploitation is currently unlikely in the wild. The most plausible attack vector is through crafted input submitted to administrative functions of the plugin; this inference is made based on the fact that the vulnerability involves SQL injection and no direct attack vector is disclosed in the description.
OpenCVE Enrichment