VDB
CVE-2024-3067
CVE-2024-3067
PUBLISHED
CVSS 7.199999809265137 HIGH
The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can also be used by unauthenticated attackers to inject malicious web scripts.
EPSS 0.68% · 51.1th percentile
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.68%
51.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aukejomm | WooCommerce Google Feed Manager | * |
| wpmarketingrobot | woocommerce_google_feed_manager | 0, 0 |
| aukejomm | WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping | 0 |
Timeline
- Apr 16, 2024 CVE Published
- Apr 16, 2024 CVE Updated
- Apr 17, 2024 EPSS Score
- May 12, 2024 EPSS Score
- Jul 2, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
- Aug 26, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 15, 2024 EPSS Score
- Nov 9, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Jan 25, 2025 EPSS Score
References
- https://plugins.trac.wordpress.org/browser/wp-product-feed-manager/trunk/includes/user-interface/class-wppfm-feed-editor-page.php#L34 vendor
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3070663%40wp-product-feed-manager&new=3070663%40wp-product-feed-manager&sfp_email=&sfph_mail= patch
- https://nvd.nist.gov/vuln/detail/CVE-2024-3067 advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/37bfb60d-8e2d-4c77-880c-3d17a6a434b8?source=cve url