The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
2025-03-25T06:15:38.823
2025-04-29T17:57:02.620
Analyzed
CVSSv3.1: 4.1 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | acowebs | product_labels_for_woocommerce_\(sale_badges\) | < 1.5.9 | Yes |