Impact
This vulnerability is an unauthenticated SQL Injection in WooBeWoo Product Filter Pro plugin versions up to 3.1.8. Because the plugin does not properly sanitize user input from the product filter interface, an attacker can craft malicious SQL payloads that are executed against the site's database. An exploitable input could grant the attacker read, modify, or delete data, potentially exposing sensitive customer information, compromising transactional integrity, and allowing tampering with product listings.
Affected Systems
Affected systems are WordPress sites that have the WooBeWoo Product Filter Pro plugin installed, specifically those running any version 3.1.8 or earlier. The plugin is distributed by WBW:WooBeWoo Product Filter Pro. No specific WordPress or PHP version is noted.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score is not available, making it difficult to gauge current exploitation probability, though the lack of a KEV listing means no publicly known exploits yet. The likely attack vector is through the public product filter interface, which any visitor can interact with, making authentication unnecessary. Once accessed, an attacker could achieve unauthorized database access rapidly due to the lack of input validation on the front‑end.
OpenCVE Enrichment