CVE-2023-33331

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.
Configurations

Configuration 1 (hide)

cpe:2.3:a:woo:product_vendors:*:*:*:*:*:wordpress:*:*

History

28 Apr 2026, 19:20

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.

21 Nov 2024, 08:05

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/woocommerce-product-vendors/wordpress-woocommerce-product-vendors-plugin-2-1-76-vendor-admin-sql-injection-vulnerability?_s_id=cve - Third Party Advisory () https://patchstack.com/database/vulnerability/woocommerce-product-vendors/wordpress-woocommerce-product-vendors-plugin-2-1-76-vendor-admin-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 8.5

22 Dec 2023, 09:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
First Time Woo product Vendors
Woo
CPE cpe:2.3:a:woo:product_vendors:*:*:*:*:*:wordpress:*:*
References () https://patchstack.com/database/vulnerability/woocommerce-product-vendors/wordpress-woocommerce-product-vendors-plugin-2-1-76-vendor-admin-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/woocommerce-product-vendors/wordpress-woocommerce-product-vendors-plugin-2-1-76-vendor-admin-sql-injection-vulnerability?_s_id=cve - Third Party Advisory

19 Dec 2023, 13:42

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 23:15

Updated : 2026-04-28 19:20


NVD link : CVE-2023-33331

Mitre link : CVE-2023-33331

CVE.ORG link : CVE-2023-33331


JSON object : View

Products Affected

woo

  • product_vendors
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')