Executive brief
eShipper Commerce is a WordPress plugin for e-commerce functionality. A SQL injection vulnerability allows subscribers (low-privileged users) to execute arbitrary database queries, potentially exposing, modifying, or deleting customer data, orders, and payment information from the site's database.
Technical details
A SQL injection vulnerability exists in eShipper Commerce plugin versions up to 2.16.13, reachable by subscribers (authenticated users with minimal privileges). The vulnerability allows an attacker to inject arbitrary SQL commands into a database query through an unvalidated or insufficiently sanitized input parameter. An authenticated subscriber can exploit this to read, modify, or delete database records including user credentials, customer information, and transactional data. The attack requires subscriber-level account access but no official patch was available as of the advisory publication date; Patchstack issued a mitigation rule to block exploitation attempts.
Affected products
- eShipper Commerce <= 2.16.13
Timeline
- 2026-08-20: disclosed
- 2026-02-23: other: Reported by hivesec