Impact
The Saad Iqbal APIExperts Square for WooCommerce plugin contains an SQL injection flaw (CWE‑89) caused by improper neutralization of special elements in SQL commands. The vulnerability permits blind SQL injection, enabling an attacker to inject and execute arbitrary SQL statements against the plugin’s database. An attacker could therefore read, modify, or delete sensitive e‑commerce data stored in the WordPress site’s database, compromising the confidentiality and integrity of the shop’s information.
Affected Systems
The vulnerable asset is the WordPress plugin APIExperts Square for WooCommerce by Saad Iqbal. All released versions up to and including version 4.7.4 are affected, so any WordPress site that has this plugin installed in those versions is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity flaw that could lead to database compromise. The EPSS score of less than 1 % suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Based on the description, the likely attack vector is via web requests to the plugin’s API or administrative endpoints that accept user‑supplied parameters. The flaw can be exploited without authentication if the API endpoints are publicly accessible, or by an authenticated user with write permissions to the plugin’s data, underscoring the seriousness of this issue.
OpenCVE Enrichment