Impact
The WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin versions 2.10.22 and earlier contain a classic SQL injection flaw. An attacker who has administrator access can supply malicious SQL code through certain input fields, causing the plugin to execute arbitrary queries against the site database. This vulnerability not only permits an attacker to read, modify, or delete database contents, but may also be leveraged for more extensive compromise if other application weaknesses are present. The flaw is classified under CWE‑89, which highlights the lack of proper input validation and prepared statement usage.
Affected Systems
All WordPress sites that employ the Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin at or below version 2.10.22 are affected. The plugin is provided by Sender.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation, suggesting that the vulnerability is not likely to be widely exploited. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local authentication: an attacker who gains administrator privileges on the WordPress site can exploit the SQL injection to read or alter sensitive data, potentially escalating privileges or compromising the entire system.
OpenCVE Enrichment