WordPress's WooCommerce Fixes SQL Injection 07-25-2021, 02:09 AM
#1
Looks like input sanitization practices are still bad, even though it's 2021. Many websites run this plugin and it's likely that a good portion still need to be updated.
Read More: https://www.bleepingcomputer.com/news/se...ata-theft/
Quote:WooCommerce, the popular e-commerce plugin for the WordPress content management system has been updated to patch a serious vulnerability that could be exploited without authentication.
Administrators are urged to install the latest release of the platform as the flaw affects more than 90 versions starting with 5.5.0.
Owned by Automattic, the company behind the WordPress.com blogging service, the WooCommerce plugin has more than five million installations.
Read More: https://www.bleepingcomputer.com/news/se...ata-theft/
![[Image: fSEZXPs.png]](https://i.imgur.com/fSEZXPs.png)