{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "3.3.0"
              },
              {
                "fixed": "3.3.6"
              },
              {
                "introduced": "3.4.0"
              },
              {
                "fixed": "3.4.8"
              },
              {
                "introduced": "3.5.0"
              },
              {
                "fixed": "3.5.9"
              },
              {
                "introduced": "3.6.0"
              },
              {
                "fixed": "3.6.6"
              },
              {
                "introduced": "3.7.0"
              },
              {
                "fixed": "3.7.2"
              },
              {
                "introduced": "3.8.0"
              },
              {
                "fixed": "3.8.2"
              },
              {
                "introduced": "3.9.0"
              },
              {
                "fixed": "3.9.4"
              },
              {
                "introduced": "4.0.0"
              },
              {
                "fixed": "4.0.2"
              },
              {
                "introduced": "4.1.0"
              },
              {
                "fixed": "4.1.2"
              },
              {
                "introduced": "4.2.0"
              },
              {
                "fixed": "4.2.3"
              },
              {
                "introduced": "4.3.0"
              },
              {
                "fixed": "4.3.4"
              },
              {
                "introduced": "4.4.0"
              },
              {
                "fixed": "4.4.2"
              },
              {
                "introduced": "4.5.0"
              },
              {
                "fixed": "4.5.3"
              },
              {
                "introduced": "4.6.0"
              },
              {
                "fixed": "4.6.3"
              },
              {
                "introduced": "4.7.0"
              },
              {
                "fixed": "4.7.2"
              },
              {
                "introduced": "4.8.0"
              },
              {
                "fixed": "4.8.1"
              },
              {
                "introduced": "4.9.0"
              },
              {
                "fixed": "4.9.3"
              },
              {
                "introduced": "5.0.0"
              },
              {
                "fixed": "5.0.1"
              },
              {
                "introduced": "5.1.0"
              },
              {
                "fixed": "5.1.1"
              },
              {
                "introduced": "5.2.0"
              },
              {
                "fixed": "5.2.3"
              },
              {
                "introduced": "5.3.0"
              },
              {
                "fixed": "5.3.1"
              },
              {
                "introduced": "5.4.0"
              },
              {
                "fixed": "5.4.2"
              },
              {
                "introduced": "5.5.0"
              },
              {
                "fixed": "5.5.1"
              }
            ]
          },
          "events": [
            {
              "introduced": "8539649e4e1a99c42b64fd203ee382b65124fb94"
            },
            {
              "fixed": "10aedc7c9be0aa7504ff3ef9401eac7eb51e6e95"
            },
            {
              "introduced": "e8d8e25de1f0a43e9bd89f1c54625ede125a2b97"
            },
            {
              "fixed": "c38e869e7d64e7e85031ba2a26bdb1ceadde6ed6"
            },
            {
              "introduced": "703ae4d26d035d77dd9dd7bda797f03f7c0bf9d2"
            },
            {
              "fixed": "ae7f2a691720cf78744dacde9d12b586ae5f01b1"
            },
            {
              "introduced": "e6d3979edb3d2a0798cd4ffd3ae75cc4db85dcc8"
            },
            {
              "fixed": "1b144ae839f0d86a81d2b2f99ccd84de858b50d3"
            },
            {
              "introduced": "106e7cc32b3546e6b5aa79ccbf1f2f9c20c5c573"
            },
            {
              "fixed": "4cbb4a882c60b44ccb0b156aaae6d94167e42301"
            },
            {
              "introduced": "163aaa029dc57b1b04f6ca583bc04c4c4e1b6767"
            },
            {
              "fixed": "ead0e524eec4ff54c14b20810d497fd8cc1cd3e4"
            },
            {
              "introduced": "e6af6820a99c6006da43fbdf7de946307e054067"
            },
            {
              "fixed": "4fec0b34927089c6a84b46aed363d054a0fe7730"
            },
            {
              "introduced": "3b1dbb06d8e9b4aff6eb6c4e3b260d786e435735"
            },
            {
              "fixed": "901dbd2d29ca87aaeaebaa486981f65da1c1a52c"
            },
            {
              "introduced": "1f739fb86207e1884607adf95c7e86f048c06e23"
            },
            {
              "fixed": "d5bafc3fd75c40600b7f4f9bdfc4e99ae33d1981"
            },
            {
              "introduced": "b2a0e738669ce9a9eb299180a02902a4322664b1"
            },
            {
              "fixed": "139515fe64e7920d71946fad426d70c9c262e413"
            },
            {
              "introduced": "d5ca9a7e14d06a75568a5a747fa97c0cf7e0c2b3"
            },
            {
              "fixed": "62fac9f0614397d58451e94da961de4d306e8353"
            },
            {
              "introduced": "20168d51fb8e034b4647b15cd011d2b23f924b02"
            },
            {
              "fixed": "c8ed6e03848995c348a3d6a8f27c136cc011bb21"
            },
            {
              "introduced": "5ad66cf50602eefcb3320ee26a5eee8d8d882417"
            },
            {
              "fixed": "9af8cb15be530f0d195cd671ae07e549150e87bc"
            },
            {
              "introduced": "e4df3529d403aca0dd4e502bbd9c1670c9e1395e"
            },
            {
              "fixed": "5d642df1e145e5f33cbda31e6d97c969df120e42"
            },
            {
              "introduced": "e5696a0d99c0f6cc4202ea4c16fd35a0875f0509"
            },
            {
              "fixed": "1fa9d156cd63afb44501675c3e4ce2f4768d44af"
            },
            {
              "introduced": "6160b25338a48a6efe96c4bc1edcbe3fb1c087f2"
            },
            {
              "fixed": "1244530ee57d348cf8b558fe2c312ab0989c70e3"
            },
            {
              "introduced": "0ec2d695b0d265dbbc151ff24c8344ac34567029"
            },
            {
              "fixed": "74d5679ff631ba7ac957ed4cee411147de47ff57"
            },
            {
              "introduced": "66a1c169f749a03e090cf66c6ee032580dcdf424"
            },
            {
              "fixed": "3eeb0f220dfe1088e7014f05d6ca272f3656b265"
            },
            {
              "introduced": "1d6a44ddb17fa4bbd17ecfcd03f5924219a22fcc"
            },
            {
              "fixed": "67a8bdbc73cd880226172cee358523cff8fb5080"
            },
            {
              "introduced": "90def7c366a63a2d7c522a34cf7992939eedd145"
            },
            {
              "fixed": "7f2346ebabc55383fcac703841acc3e1bb47a885"
            },
            {
              "introduced": "5d2e89d727723993546593f96c0440936e50e6dc"
            },
            {
              "fixed": "3f869efe06b32462cea259b836f48933de3d76df"
            },
            {
              "introduced": "b11ba623192b9f68ebcc0341140b87255054a05f"
            },
            {
              "fixed": "0c8e3dd875c2796a3fec176a4c71c04f6770c016"
            },
            {
              "introduced": "8b343f4e1bbc45f063158780d31094b2956b838f"
            },
            {
              "fixed": "7b4211276162f7e44868847b72eba655d7b93f52"
            }
          ],
          "repo": "https://github.com/woocommerce/woocommerce",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-json/wc/v3/webhooks`, `/wp-json/wc/v2/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a patch for this vulnerability. There are no known workarounds other than upgrading.",
  "id": "CVE-2021-32790",
  "modified": "2026-03-13T21:53:56.271186798Z",
  "published": "2021-07-26T17:15:08Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://woocommerce.com/posts/critical-vulnerability-detected-july-2021/"
    },
    {
      "type": "FIX",
      "url": "https://github.com/woocommerce/woocommerce/security/advisories/GHSA-7vx5-x39w-q24g"
    }
  ],
  "related": [
    "GHSA-7vx5-x39w-q24g"
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}