Impact
The vulnerability lies in the Price Drop Alert for Woo Commerce WordPress plugin version 1.1. An AJAX action available to any visitor does not escape or sanitize incoming parameters before incorporating them into a SQL query. This flaw permits an unauthenticated attacker to inject arbitrary SQL, enabling extraction of sensitive database contents such as user credentials, order information, and other confidential data.
Affected Systems
The affected product is the Price Drop Alert for Woo Commerce plugin for WordPress, any installation of version 1.1 or earlier. No other vendor or product variants are listed.
Risk and Exploitability
The CVSS score of 8.6 classifies this as a high‑severity issue, yet the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog, but the attack vector is straightforward: a web application call to an unsecured AJAX endpoint. An attacker can execute the injection from any IP address without authentication, revealing sensitive data and potentially allowing further compromise.
OpenCVE Enrichment