QID 730797

Date Published: 2023-05-10

QID 730797: WordPress Plugin Enhanced-e-commerce-for-woocommerce-store SQL Injection Vulnerability

Enhanced-e-commerce-for-woocommerce-store WordPress plugin helps in track everything with a single plugin and get rid of 10+ plugins from your WooCommerce store in order to make your website faster.

The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement.

Affected Versions:
Enhanced-e-commerce-for-woocommerce-store WordPress plugin versions prior to 4.6.2

QID Detection Logic(Unauthenticated):
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the enhanced-e-commerce-for-woocommerce-store plugin.

Successful exploitation of this vulnerability may allowing any authenticated user to perform SQL injection attacks.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to install Enhanced-e-commerce-for-woocommerce-store plugin version 4.6.2 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730797

    Software Advisories
    Advisory ID Software Component Link
    Enhanced-e-commerce-for-woocommerce-store Release Notes URL Logo wordpress.org/plugins/enhanced-e-commerce-for-woocommerce-store/#developers