Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Injection.This issue affects WooBeWoo Product Filter Pro: from n/a before 2.9.6.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 2.9.6
Credits
Trương Hữu Phúc / truonghuuphuc (Patchstack Bug Bounty program)
References
patchstack.com/...-7-6-sql-injection-vulnerability?_s_id=cve