mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
886 B
886 B
CVE-2024-0399
Description
The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
POC
Reference
- https://wpscan.com/vulnerability/1550e30c-bf80-48e0-bc51-67d29ebe7272/
- https://wpscan.com/vulnerability/1550e30c-bf80-48e0-bc51-67d29ebe7272/