Beta

Report

Ni WooCommerce Custom Order Status <= 1.9.6 is vulnerable to SQL Injection (SQLi) vulnerability

Subscriber
Published
2021-11-21

The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber

CVSS

Score:6.3

Severity:Medium

Version: 1.9.6

There is a patch available in v1.9.7 and we strongly recommend you update to this version as soon as possible.