Automattic: Woocommerce SQL Injection in WC_Report_Coupon_Usage
Discription

image
A SQL injection vulnerability was found in the WooCommerce plugin version 9.9.3. The vulnerable parameter was 'coupon_codes' in the '/wp-admin/admin.php?page=wc-reports&tab=orders&report=coupon_usage' endpoint. The vulnerability required the privilege to view…Read More

Back to Main

Subscribe for the latest news: