← back
CVE-2021-32790mediumobserved exploitationCWE-89

Blind SQL Injection possible via Authenticated Web-hook Search API Endpoint

35Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 4.9epss 1.3%
from disclosure to weapon
Published on NVDJul 26
VulnCheck+999d
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
yesVulnCheck
Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-json/wc/v3/webhooks`, `/wp-json/wc/v2/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a patch for this vulnerability. There are no known workarounds other than upgrading.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N