Executive brief
A security vulnerability exists in the APIExperts Square for WooCommerce plugin, which is used to integrate Square payment processing with WordPress e-commerce sites. An attacker with basic user permissions could potentially access or steal sensitive information from the website's database. This could lead to the exposure of customer data or internal site configurations, potentially damaging the business's reputation and operational security.
Technical details
The APIExperts Square for WooCommerce (woosquare) plugin for WordPress is vulnerable to a Blind SQL Injection vulnerability due to improper neutralization of special elements used in SQL commands. The flaw exists in versions up to and including 4.7.1. An attacker with 'Contributor' level privileges or higher can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to interact directly with the database to extract sensitive information. The issue has been addressed in version 4.7.2.
Affected products
- Saad Iqbal APIExperts Square for WooCommerce (woosquare) <= 4.7.1
Timeline
- 2026-01-27: other: Reported by Nguyen Ba Khanh
- 2026-03-16: advisory: Patchstack advisory published
- 2026-05-12: disclosed: CVE published to NVD