Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting <= 4.1.3 - Unauthenticated SQL Injection
high
The Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...
- CVSS:
- 7.5
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Mar 18, 2026
CVE-2026-24993 on NVD →
Advanced WooCommerce Product Sales Reporting <= 4.1.2 - Unauthenticated Information Exposure
medium
The Advanced WooCommerce Product Sales Reporting – Statistics & Forecast plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.3
- Disclosed:
- Jan 23, 2026
CVE-2026-24992 on NVD →
Advanced WooCommerce Product Sales Reporting <= 4.1.1 - Unauthenticated SQL Injection
high
The Advanced WooCommerce Product Sales Reporting plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.5
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Mar 31, 2025
CVE-2025-31553 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database