CVE-2021-32789
Description
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]
endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.
Severity: HIGH
CVE ID: CVE-2021-32789
CVSS Score: 7.5
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Proof Of Concept
Nuclei Templates for CVE-2021-32789
Refrence: Project Discovery GitHub
and0x00
💣 Wordpress WooCommerce users dump exploit.
Refrence: GitHub
DonVorrin
Authenticated Blind SQL Injection. Wordpress woocommerce plugin versions >= 2.5.0
Refrence: GitHub