← Back

CVE-2021-32789

Published: Jul 26, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.

Affected (31)

1 product
Woocommerce Blocks
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Automattic
From 2.5.0 to 2.5.16
From 2.6.0 to 2.6.2
From 2.7.0 to 2.7.2
From 2.8.0 to 2.8.1
From 2.9.0 to 2.9.1
From 3.0.0 to 3.0.1
From 3.1.0 to 3.1.1
From 3.2.0 to 3.2.1
From 3.3.0 to 3.3.1
From 3.4.0 to 3.4.1
From 3.5.0 to 3.5.1
From 3.6.0 to 3.6.1
From 3.7.0 to 3.7.2
From 3.8.0 to 3.8.1
From 3.9.0 to 3.9.1
From 4.0.0 to 4.0.1
From 4.1.0 to 4.1.1
From 4.2.0 to 4.2.1
From 4.3.0 to 4.3.1
From 4.4.0 to 4.4.3
From 4.5.0 to 4.5.3
From 4.6.0 to 4.6.1
From 4.7.0 to 4.7.1
From 4.8.0 to 4.8.1
From 4.9.0 to 4.9.2
From 5.0.0 to 5.0.1
From 5.1.0 to 5.1.1
From 5.2.0 to 5.2.1
From 5.3.0 to 5.3.2
From 5.4.0 to 5.4.1
From 5.5.0 to 5.5.1

References (10)

Source: security-advisories@github.com
Permissions Required
Source: security-advisories@github.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.