Impact
The Ni WooCommerce Sales Report WordPress plugin prior to version 4.2.0 fails to sanitize the ‘sort’ parameter before incorporating it into a SQL query. This flaw permits an unauthenticated user to inject arbitrary SQL, potentially allowing data exfiltration, tampering, or deletion from the WordPress database, and could lead to broader compromises if the database contains sensitive application data.
Affected Systems
The vulnerability affects all installations of the Ni WooCommerce Sales Report WordPress plugin older than version 4.2.0. Users have not been identified by a formal vendor; the plugin is distributed under the name Ni WooCommerce Sales Report.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low, but not zero, probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV SQL injection—suggests high potential a crafted web request containing a malicious ‘sort’ value and directly influence the database query, with no authentication or special privileges required.
OpenCVE Enrichment