RULE(RULE ID:338242)

Rule General Information
Release Date: 2024-07-09
Rule Name: WordPress Plugin Dokan-Pro SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Dokan-Pro is a premium WordPress plugin that extends the functionality of WooCommerce, enabling users to create a feature-rich, multi-vendor marketplace with advanced management and customization options.The Dokan Pro plugin has a SQL injection vulnerability in versions 3.10.3 and below due to insufficient escaping of the 'code' parameter provided by users and inadequate preparation of existing SQL queries. Unauthorized attackers can exploit this vulnerability to inject additional SQL statements into the existing query, thereby extracting sensitive information from the database.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.