CVE-2024-10638: Product Labels For Woocommerce < 1.5.11 - Admin+ SQLi
Published Mar 25, 2025
·Updated
The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
2 affected components
WordPress Product Labels For Woocommerce<1.5.11
acowebs Product Labels For Woocommerce \(sale Badges\) Wordpress<1.5.11
Event History
Mar 25, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10638?
CVE-2024-10638 has a high severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-10638?
To fix CVE-2024-10638, update the Product Labels For Woocommerce plugin to version 1.5.11 or later.
3
Who is affected by CVE-2024-10638?
Administrators using Product Labels For Woocommerce versions prior to 1.5.11 are affected by CVE-2024-10638.
4
What type of vulnerability is CVE-2024-10638?
CVE-2024-10638 is classified as an SQL injection vulnerability.
5
What could an attacker do with CVE-2024-10638?
An attacker could exploit CVE-2024-10638 to execute arbitrary SQL queries, compromising the site's data.