Impact
An input validation flaw in Zorem Advanced Shipment Tracking for WooCommerce allows an attacker to inject malicious SQL code into a query without immediate error feedback. The flaw is classified as CWE-89. Based on the description, it is inferred that this results in blind SQL injection, meaning that while the attacker may not see query output, they may infer data from application responses or manipulate the database content. Successful exploitation can lead to retrieval of sensitive information such as order details, customer data, or credentials, and may grant the attacker unauthorized data modification capabilities.
Affected Systems
The vulnerability affects the WordPress plugin Zorem Advanced Shipment Tracking for WooCommerce, including all released versions up to and including 4.0. Users running any version of this plugin on a WordPress site are at risk unless the plugin has been upgraded beyond version 4.0 or otherwise mitigated.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity of exploitation impact. The EPSS score of less than 1% implies a very low probability of widespread exploitation at this time. The vulnerability is currently not listed in the CISA KEV catalog. Attackers would most likely leverage the web interface of the plugin, sending specially crafted requests that trigger the underlying SQL queries. Because the injection is blind, an attacker can employ timing or inferred‑data techniques to extract information without explicit feedback. Responders should treat this as a high‑priority issue, given the potential for confidential data exposure and the simplicity of the exploit path.
OpenCVE Enrichment