High severity8.1NVD Advisory· Published Apr 15, 2024· Updated Jun 17, 2026
CVE-2024-0399
CVE-2024-0399
Description
The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:vanquish:woocommerce_customers_manager:*:*:*:*:*:wordpress:*:*Range: <29.7
- Range: <29.7
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/1550e30c-bf80-48e0-bc51-67d29ebe7272/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.