Impact
The vulnerability resides in the WooCommerce plugin before version 11.0. Improper handling of special characters in SQL commands allows a blind SQL injection, enabling an attacker to enumerate, exfiltrate or tamper with database contents.
Affected Systems
Affected products are the Automattic WooCommerce plugin for WordPress, all releases older than 11.0. No specific subversion details are provided; the issue applies to any version flagged as earlier than 11.0.
Risk and Exploitability
The risk assessment shows a CVSS score of 7.6, considered high. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploitation. The likely attack vector is through the plugin's web interfaces that construct SQL queries without proper sanitization. Until the plugin is updated to 11.0 or later, the system remains vulnerable.
OpenCVE Enrichment