{"id":"CVE-2021-32789","details":"woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.","aliases":["GHSA-6hq4-w6wv-8wrp"],"modified":"2026-08-27T03:56:00.282795674Z","published":"2021-07-26T16:15:07.743Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"automattic:woocommerce_blocks","cpes":["cpe:2.3:a:automattic:woocommerce_blocks:*:*:*:*:*:wordpress:*:*"],"extracted_events":[{"introduced":"2.6.0"},{"fixed":"2.6.2"},{"introduced":"2.8.0"},{"fixed":"2.8.1"},{"introduced":"2.9.0"},{"fixed":"2.9.1"},{"introduced":"3.0.0"},{"fixed":"3.0.1"},{"introduced":"3.2.0"},{"fixed":"3.2.1"},{"introduced":"3.3.0"},{"fixed":"3.3.1"},{"introduced":"3.5.0"},{"fixed":"3.5.1"},{"introduced":"3.7.0"},{"fixed":"3.7.2"},{"introduced":"3.9.0"},{"fixed":"3.9.1"},{"introduced":"4.1.0"},{"fixed":"4.1.1"},{"introduced":"4.2.0"},{"fixed":"4.2.1"},{"introduced":"4.3.0"},{"fixed":"4.3.1"},{"introduced":"4.5.0"},{"fixed":"4.5.3"},{"introduced":"4.6.0"},{"fixed":"4.6.1"},{"introduced":"4.8.0"},{"fixed":"4.8.1"},{"introduced":"5.0.0"},{"fixed":"5.0.1"},{"introduced":"5.2.0"},{"fixed":"5.2.1"},{"introduced":"5.4.0"},{"fixed":"5.4.1"}]}]},"references":[{"type":"ADVISORY","url":"https://woocommerce.com/posts/critical-vulnerability-detected-july-2021/"},{"type":"REPORT","url":"https://hackerone.com/reports/1260787"},{"type":"REPORT","url":"https://wooengineering.wordpress.com/2021/07/14/incident-report-sql-injection-via-store-api/"},{"type":"FIX","url":"https://github.com/woocommerce/woocommerce-gutenberg-products-block-ghsa-6hq4-w6wv-8wrp/pull/1"},{"type":"FIX","url":"https://github.com/woocommerce/woocommerce-gutenberg-products-block/security/advisories/GHSA-6hq4-w6wv-8wrp"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/woocommerce/woocommerce-blocks","events":[{"introduced":"76fdbe3c36ca43ac6117a7dfb50ad8d2e4e71aa1"},{"fixed":"3bd91b669247000fd3f5277954701d0b148d3f1a"},{"introduced":"161be65dbff230862fe52a18ea7c9a01557169c2"},{"fixed":"22a19698c5d0bf0029f10d39928d6fa54fc50ffd"},{"introduced":"934285477b34645deb1cbe36c2609b2c502163d6"},{"fixed":"67f72c7b53c21eddfc75edd378d3a630564a20e3"},{"introduced":"af29d12f09a2eecf1d1776d96197723587c8628c"},{"fixed":"fb8ec657132610adfb415b669b7bebc3e9ef7b4c"},{"introduced":"cefff7a40aae2b5ac0f9a0d9561209538d6ce4c1"},{"fixed":"eb4bf677e94def44686c8fdb3ba1362f19743053"},{"introduced":"aa896f9ca2918f37221b314c34f249be1d751f0e"},{"fixed":"a3cc0ef6f6a00288d4a59dbcd84a68b5224f7712"},{"introduced":"b498011329565d6f28b78bef32b8e0aba52ef8c8"},{"fixed":"d7232c7c9fb7294ddbdcc1429752ffcbaf9dc148"},{"introduced":"a3bfc03be32d93afad185ffeeebdb9faf608debc"},{"fixed":"6c8dbcd9f0bb745c7288da80bb3b7e48178777e2"},{"introduced":"b097b2553f863f2c97d647ebdf4e47253070e107"},{"fixed":"443766c8fa918e78521e8bff7bc31ebe8b9d8363"},{"introduced":"fd34b7626767d4930452978f5441329872aaa2a3"},{"fixed":"3ba866b4a5f8eb62dd69a5103ce36eabfaebbed2"},{"introduced":"7ca3ed0aa5fc7a5967fcd782a8627f326ca050b3"},{"fixed":"900140d147630e65e3b61eba094f364f76a0ac5b"},{"introduced":"2fd8984e7895cbd07e2afde222349ad574dcf3e4"},{"fixed":"7a34a45978a7a638d85ca05bd6e70c5b85383bc4"},{"introduced":"d306dfe5d9451755034fa77563d5fd3e7f497ccb"},{"fixed":"0d94aa58744d5b9d92e419bef8d9399ae93901e8"}],"database_specific":{"extracted_events":[{"introduced":"2.5.0"},{"fixed":"2.5.16"},{"introduced":"2.7.0"},{"fixed":"2.7.2"},{"introduced":"3.1.0"},{"fixed":"3.1.1"},{"introduced":"3.4.0"},{"fixed":"3.4.1"},{"introduced":"3.6.0"},{"fixed":"3.6.1"},{"introduced":"3.8.0"},{"fixed":"3.8.1"},{"introduced":"4.0.0"},{"fixed":"4.0.1"},{"introduced":"4.4.0"},{"fixed":"4.4.3"},{"introduced":"4.7.0"},{"fixed":"4.7.1"},{"introduced":"4.9.0"},{"fixed":"4.9.2"},{"introduced":"5.1.0"},{"fixed":"5.1.1"},{"introduced":"5.3.0"},{"fixed":"5.3.2"},{"introduced":"5.5.0"},{"fixed":"5.5.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:automattic:woocommerce_blocks:*:*:*:*:*:wordpress:*:*"}}],"versions":["v4.9.1","v5.1.0","v4.0.0","v3.6.0","v3.4.0","v3.1.0","v5.5.0-dev","v5.3.1-dev","v5.3.0-dev","v5.1.0-dev","v4.9.1-dev","v4.7.0-dev","v4.9.0-dev","v4.0.0-dev","v3.8.0-dev","v3.6.0-dev","v3.4.0-dev","v3.1.0-dev"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32789.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}