MStore API < 3.9.8 – Unauthenticated Blind SQLi
Discription

The plugin does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins’ pro features, and uses the woocommerce-appointments plugin.Read More

Back to Main

Subscribe for the latest news: