S4E just found a low-severity finding from [ai] web application external link detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-32789 Scanner

CVE-2021-32789 scanner - SQL Injection vulnerability in Gutenberg Blocks plugin for WooCommerce

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-32789
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
woocommerce-gutenberg-products-blockby woocommerce
> 2.5.0, < 2.5.16
Updated Aug 21, 2026View on NVD →
Detail

The Gutenberg Blocks plugin for WooCommerce is a feature that provides a seamless experience for e-commerce store owners. This plugin allows store owners to easily create custom product layouts, including arranging product images, descriptions, prices, and more. It removes the need for tedious coding, and allows store owners to build their store quickly and easily. With the Gutenberg Blocks plugin, the store owner can create a website that is visually appealing, responsive, and functional in a less amount of time.

The CVE-2021-32789 vulnerability is a security vulnerability detected in the Gutenberg Blocks plugin. It impacts all WooCommerce sites running versions of the plugin between 2.5.0 and prior to version 2.5.16. The vulnerability is an SQL injection vulnerability that could allow an attacker to execute a read-only SQL query against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint. This is a serious vulnerability because it could allow an attacker to extract sensitive information from an e-commerce site without being detected.

If exploited, the CVE-2021-32789 vulnerability could lead to the exposure of sensitive information like customer names, addresses, and payment information. An attacker could leverage this information for identity theft, credit card fraud, or other harmful purposes. The sensitive information could also be sold on the dark web to other attackers who could use it for more advanced attacks. Ultimately, an attacker could cause harm to both the e-commerce store owner and the customers.

Thanks to the pro features of the s4e.io platform, those who are reading this article can easily and quickly learn about vulnerabilities that may be present in their digital assets. With s4e.io, it is easy to detect, analyze, and remediate vulnerabilities before they become a problem. Store owners can relax knowing their website is safe and secure from potential attackers. Sign up for s4e.io today, and be confident in the security of your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, store owners can take the following precautions:

  • Upgrade to version 2.5.16 or higher of the WooCommerce Blocks feature plugin.
  • Install security plugins such as Wordfence, Sucuri, or iThemes Security on the website. 
  • Regularly back up the website to prevent loss of data due to a successful attack.
  • Review and disable any outdated or unused plugins on the website.
  • Monitor website activity for any signs of a breach or suspicious behavior.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-32789 scanner - SQL Injection vulnerability in Gutenberg Blocks plugin for WooCommerce | S4E