Lucene search

K
nvd[email protected]NVD:CVE-2024-0399
HistoryApr 15, 2024 - 5:15 a.m.

CVE-2024-0399

2024-04-1505:15:14
web.nvd.nist.gov
woocommerce
customers manager
sql injection
wordpress
subscriber+ role
cve-2024-0399

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for NVD:CVE-2024-0399