Impact
Unauthenticated SQL Injection exists in WordPress Woo Essential plugin versions up to 4.3.0. Attackers can input malicious SQL through plugin parameters without authentication. This flaw permits attackers to read, modify, or delete database contents, potentially exposing sensitive data such as customers, orders, or credentials. The impact ranges from data compromise to full control of the website’s database, depending on the attacker’s ability to leverage the injection for further exploitation.
Affected Systems
The vulnerability affects the DiviNext Woo Essential plugin for WordPress up to version 4.3.0. Any WordPress site that has this plugin installed and has not upgraded to a later release is at risk. No specific operating system or PHP version restrictions are noted; attackers only require network access to the site.
Risk and Exploitability
The CVSS score of 9.3 marks it as critical. Because the vulnerability is unauthenticated and can be leveraged through a web request, an attacker only needs to reach the plugin endpoint, making exploitation relatively simple if the plugin is still in use. While EPSS data is unavailable, the severity indicates a high likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, but its critical score and unauthenticated nature make it a pressing risk for all affected installations.
OpenCVE Enrichment