Impact
The Ni WooCommerce Sales Report WordPress plugin, before version 4.2.0, has a vulnerability that fails to sanitize the ‘sort’ parameter before inserting it into a SQL query, enabling unauthenticated users to perform SQL injection. Attackers can exploit this flaw to read, modify, or delete data stored in the WordPress database, potentially compromising confidentiality, integrity, and availability of stored records.
Affected Systems
All installations of the Ni WooCommerce Sales Report plugin older than 4.2.0 are affected, regardless of site owner or hosting environment. The plugin is distributed under the name Ni WooCommerce Sales Report and there is no identified corporate vendor.
Risk and Exploitability
The CVSS base score of 8.6 indicates high severity. With an EPSS score of less than 1 % the probability of exploitation in the wild is very low, and the vulnerability is not listed in the CISA KEV. The flaw can be triggered by any user sending a request containing a malicious ‘sort’ value. No authentication is required to reach the vulnerable code path. If successfully exploited, the attacker could perform unauthorized database operations.
OpenCVE Enrichment