Input validation vulnerability in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes 1.4.8

A plugin called ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes for WordPress has a security issue called SQL Injection. This means that someone with shop manager-level access or higher can add their own code to the plugin’s existing code, which could give them access to private information stored in the website’s database. This vulnerability exists in versions 1.4.8 and below.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.