Executive brief
APIExperts Square for WooCommerce is a WordPress plugin used to integrate Square payment processing with online stores. A security flaw in this plugin allows an attacker with a basic user account to perform blind SQL injection attacks. This could lead to the unauthorized extraction of sensitive information from the website's database, potentially compromising customer data or site configuration.
Technical details
A Blind SQL Injection vulnerability exists in the Saad Iqbal APIExperts Square for WooCommerce (woosquare) plugin for WordPress. The flaw is caused by improper neutralization of special elements used in an SQL command (CWE-89). An attacker with 'Subscriber' level privileges or higher can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to directly interact with the database to extract sensitive information. The issue affects all versions up to and including 4.7.4; it is fixed in version 4.7.5.
Affected products
- Saad Iqbal APIExperts Square for WooCommerce (woosquare) <= 4.7.4
Timeline
- 2026-06-02: other: Reported by researcher Averon Averenkov
- 2026-07-09: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD
- 2026-07-13: patched: Version 4.7.5 released to address the vulnerability