Impact
Administrator SQL injection is present in MC Woocommerce Wishlist Plugin versions up to 1.9.21. The flaw enables an attacker who can submit malicious input to the plugin’s database queries to execute arbitrary SQL statements. This could result in disclosure of sensitive data, modification of orders or customer records, or deletion of critical information, compromising the confidentiality and integrity of the site’s data.
Affected Systems
The vulnerability is limited to the MC Woocommerce Wishlist plugin developed by the Moreconvert Team for WordPress. All instances of the plugin with a version of 1.9.21 or earlier are affected.
Risk and Exploitability
The CVSS score of 7.6 indicates a high risk level. The EPSS score is not available, so the exact likelihood of exploitation is uncertain, but the absence from the CISA KEV list suggests no publicly known exploits at this time. The likely attack vector is through the plugin’s administrator interface, requiring authenticated administrative access to trigger the injection vector. Without such access, exploitation is less probable.
OpenCVE Enrichment