Input validation vulnerability in WooCommerce Multilingual & Multicurrency with WPML 5.3.3.1

The plugin called “WooCommerce Multilingual & Multicurrency with WPML” for WordPress can be hacked through a method called SQL Injection. This is because the plugin does not properly protect against user input and does not properly prepare for existing SQL queries. This vulnerability can allow hackers with shop manager-level access or higher to add their own SQL queries to ones that already exist, potentially accessing sensitive information from the database.

Detected in:

WPML Multilingual & Multicurrency for WooCommerce fixed vulnerable versions: >= * <= 5.3.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.