Impact
The vulnerability is a Contributor SQL Injection that allows an attacker to inject arbitrary SQL statements into database queries through the Suggestion Engine for WooCommerce plugin’s input handling. If successful, the attacker may read, modify or delete data stored in the site’s database, potentially exposing sensitive information or compromising site integrity. The weakness stems from insufficient sanitization of user-supplied input before it is used in SQL statements.
Affected Systems
The plugin is developed by VillaTheme and is distributed as the Suggestion Engine for WooCommerce WordPress extension. All installations of this plugin that are version 2.0.11 or earlier are affected. No additional affected versions are noted in the available data.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity flaw. The EPSS score is not available, so the precise probability of exploitation cannot be calculated; the absence from CISA KEV suggests no widespread exploitation has been documented yet. Based on the nature of the flaw, the likely attack vector is remote, involving crafted HTTP requests that can be submitted through the plugin’s frontend or backend interfaces. Successful exploitation would grant an attacker the ability to perform unauthorized database operations, leading to potential data exfiltration, corruption, or denial service.
OpenCVE Enrichment