CVE-2024-56290
WordPress Multiple Shipping And Billing Address For Woocommerce Plugin <= 1.2 - Unauthenticated SQL Injection vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through 1.2.
Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en silverplugins217 Multiple Shipping And Billing Address For Woocommerce permite la inyección SQL. Este problema afecta a Multiple Shipping And Billing Address For Woocommerce: desde n/a hasta 1.2.
The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-12-18 CVE Reserved
- 2025-01-03 CVE Published
- 2025-01-08 CVE Updated
- 2025-01-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
- CAPEC-66: SQL Injection
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Different Shipping And Billing Address For Woocommerce Search vendor "Different Shipping And Billing Address For Woocommerce" | Different Shipping And Billing Address For Woocommerce Search vendor "Different Shipping And Billing Address For Woocommerce" for product "Different Shipping And Billing Address For Woocommerce" | >= 0.0 <= 1.2 Search vendor "Different Shipping And Billing Address For Woocommerce" for product "Different Shipping And Billing Address For Woocommerce" and version " >= 0.0 <= 1.2" | en |
Affected
|