Impact
An attacker can inject arbitrary SQL through the shop manager interface of the Persian Woocommerce SMS plugin in WordPress, allowing manipulation and retrieval of database contents. The vulnerability, classified as CWE‑89, can lead to data theft and corruption, and based on the description it is inferred that unauthorized code execution might be possible if the database is leveraged in such a way. The attack could compromise customer records, order data, and other sensitive information stored in the WooCommerce database.
Affected Systems
The weakness affects the PersianScript Persian Woocommerce SMS plugin for WordPress. All releases up to version 7.2.2 are vulnerable; versions 7.2.3 and above presumably contain the fix. The plugin integrates with WooCommerce and is used to send SMS notifications to customers; the shop manager role can access the vulnerable interface.
Risk and Exploitability
With a CVSS v3.1 score of 7.6, the vulnerability carries high severity. The EPSS score of less than 1% indicates that the exploitation probability is low at this time, and it is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector requires authentication as a shop manager to reach the vulnerable input, after which a crafted SQL payload could be executed against the backend database. The low EPSS suggests that, while possible, malicious actors may not yet be targeting this plugin extensively.
OpenCVE Enrichment