CVE Database /
CVE-2021-32790
CVE · Medium
CVE-2021-32790 — WooCommerce [woocommerce] < 6.6.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-32790
|
WooCommerce [woocommerce] < 6.6.0 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Medium
4.9
|
< 6.6.0
|
6.6.0 |
2021-07-13 |
—
|
CVE-2021-32790
WooCommerce versions 3.3.0 through 3.3.6 contain an SQL injection flaw in webhook-related API endpoints including `/wp-json/wc/v3/webhooks` and `/wp-json/wc/v2/webhooks`. Attackers with administrative privileges or valid API keys can craft malicious search parameters to execute read-only SQL queries and extract sensitive information through timing-based attacks. The vulnerability was patched beginning with version 3.3.6, and upgrading is the only available mitigation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings