Product Filter For WooCommerce Product <= 1.3.1 - Unauthenticated SQL Injection
highThe Product Filter For WooCommerce Product plugin for WordPress is vulnerable to SQL Injection via the `datastring` paramater in versions up to and including 1.3.1. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive i...
- CVSS:
- 7.5
- Affected:
- up to 1.3.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 14, 2022