Ni WooCommerce Custom Order Status <= 1.9.6 - SQL Injection
highThe get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated u...
- CVSS:
- 8.8
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.7
- Disclosed:
- Nov 22, 2021