Impact
The License Manager for WooCommerce plugin up to version 3.0.18 contains a flaw that enables an attacker to inject arbitrary SQL statements into the queries used to manage license data. Exploitation can lead to reading, modifying, or deleting records stored in the WordPress database, potentially exposing sensitive information or corrupting site data.
Affected Systems
WordPress sites that have installed the Saad Iqbal:License Manager for WooCommerce plugin version 3.0.18 or earlier are affected. Any installation of these versions without a patch remains vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies this issue as high risk, and the EPSS score is not available while the vulnerability is not listed in the CISA KEV catalog. The likelihood of exploitation depends on the plugin’s input handling; it is inferred that the attack vector is web‑based, possibly through form submissions or URL parameters that manipulate license queries. Successful exploitation may require a user with permission to access the license interface, though the exact prerequisites are not detailed in the advisory.
OpenCVE Enrichment