Stripe Payment Plugin for WooCommerce for WordPress versions up to 3.7.9 contains a sql_injection caused by insufficient escaping and lack of preparation on 'id' parameter, letting unauthenticated attackers execute arbitrary SQL queries, exploit requires sending crafted 'id' parameter.
id: CVE-2024-0705
info:
name: Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQ
...