CVE-2024-22147: WordPress WooCommerce PDF Invoices & Packing Slips Plugin <= 3.7.5 is vulnerable to SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects PDF Invoices & Packing Slips for WooCommerce: from n/a through 3.7.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WooCommerce PDF Invoices & Packing Slips Pluginto a version that resolves this vulnerability.Fixed in 3.7.6
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22147?
CVE-2024-22147 is classified as a critical severity SQL injection vulnerability.
How do I fix CVE-2024-22147?
To fix CVE-2024-22147, you should update the WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin to version 3.7.6 or later.
What impact does CVE-2024-22147 have on my website?
CVE-2024-22147 can allow attackers to execute malicious SQL commands, potentially compromising your website's database.
Which versions are affected by CVE-2024-22147?
CVE-2024-22147 affects all versions of WP Overnight PDF Invoices & Packing Slips for WooCommerce from n/a up to and including version 3.7.5.
Is CVE-2024-22147 easy to exploit?
Yes, CVE-2024-22147 is considered easy to exploit, making it crucial to apply the necessary updates promptly.