CVE-2024-0399: WooCommerce Customers Manager < 29.7 - Subscriber+ SQL Injection
Published Apr 15, 2024
·Updated
The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
Affected Software
2 affected components
WooCommerce Customers Manager<29.7
Vanquish Woocommerce Customers Manager Wordpress<29.7
Event History
Apr 15, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionWeakness
Apr 16, 2025
Exploit Published
12:00 AM
Known Exploited
09:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-0399?
CVE-2024-0399 has a high severity rating due to the potential for SQL injection attacks.
2
How do I fix CVE-2024-0399?
To fix CVE-2024-0399, update the WooCommerce Customers Manager plugin to version 29.7 or later.
3
Who is affected by CVE-2024-0399?
Users with the WooCommerce Customers Manager plugin version earlier than 29.7 are affected, especially those with Subscriber+ roles.
4
What kind of attack does CVE-2024-0399 enable?
CVE-2024-0399 enables SQL injection attacks that can compromise the database through unvalidated input.
5
What versions of the WooCommerce Customers Manager are affected by CVE-2024-0399?
CVE-2024-0399 affects all versions of the WooCommerce Customers Manager plugin prior to version 29.7.