WPIntell

Source evidence

Vulnerable to SQL Injection

ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic) · support · 2025-04-24T04:45:00+00:00

mixedsentiment
highseverity
0.82relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

10 / 51 rows with source links

19.6% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

41 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Mehraz Morshed resolved
The plugin is vulnerable to SQL Injection via the ‘attribute_value_filter’ parameter. Hi @mehrazmorshed Thank you for bringing this to our attention. We acknowledge the issue you’ve reported regarding a potential SQL Injection vulnerability via the attribute_value_filter parameter in our plugin. Our development team is actively investigating this on our end, and we’re treating it with the highest priority. A fix will be included in an upcoming release, which we aim to make available soon. Please feel free to reach out if you have any additional information or concerns in the meantime. Thanks for the update.

Comments

2 shown
Akash 2025-04-25T11:41:00+00:00

Hi @mehrazmorshed Thank you for bringing this to our attention. We acknowledge the issue you’ve reported regarding a potential SQL Injection vulnerability via the attribute_value_filter parameter in our plugin. Our development team is actively investigating this on our end, and we’re treating it with the highest priority. A fix will be included in an upcoming release, which we aim to make available soon. Please feel free to reach out if you have any additional information or concerns in the meantime.

Mehraz Morshed 2025-04-25T11:54:00+00:00

Thanks for the update.