Impact
The GoPay for WooCommerce plugin is vulnerable to a classic SQL injection through the log_table_filter parameter in all released versions up to 1.0.36. Because the value is concatenated directly into a query without escaping or prepared statements, an attacker who can log into the site with shop‑manager level or higher privileges can inject arbitrary SQL, allowing the retrieval of any database table or the execution of destructive statements. This weakness maps to CWE‑89 and the impact is the disclosure of sensitive data and potential integrity compromise.
Affected Systems
Any installation of the GoPay for WooCommerce WordPress plugin with a version of 1.0.36 or earlier is affected. The vulnerability applies to all environments where the plugin is active, regardless of host OS or database type, as long as a shop manager+ role exists in the WordPress installation.
Risk and Exploitability
The severity reflects a moderate CVSS score of 4.9, and the EPSS shows a probability below 1 %, indicating that it is unlikely to be observed in the wild. The vulnerability is not listed in CISA’s KEV catalog, further suggesting limited exploitation. Attackers must be authenticated to a role of shop manager or higher, which limits the threat to sites with weak role separation or compromised shop‑manager accounts. Because the attack requires elevated access, the overall risk remains moderate but should be mitigated promptly.
OpenCVE Enrichment