Vulnerability Details CVE-2021-25068
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.6%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2021-25068
-
cpe:2.3:a:dpl:sync_woocommerce_product_feed_to_google_shopping:-
-
cpe:2.3:a:dpl:sync_woocommerce_product_feed_to_google_shopping:1.2.4