Security News > 2021 > July > Zero-Day Attacks on Critical WooCommerce Bug Threaten Databases

A critical SQL-injection security vulnerability in the WooCommerce e-commerce platform and a related plugin has been under attack as a zero-day bug, researchers have disclosed.
The exploitation prompted WooCommerce to release an emergency patch for the issue late on Wednesday.
The related plugin affected by the bug is the WooCommerce Blocks feature, which is installed on more than 200,000 sites.
The vulnerability affects versions 3.3 to 5.5 of the WooCommerce plugin and WooCommerce Blocks 2.5 to 5.5 plugin.
If your storefront is using WooCommerce version 5.3, you can update to version 5.3.1 to minimize the risk of compatibility issues."
WooCommerce is also recommending administrative password resets after updating to provide additional protection.
News URL
https://threatpost.com/zero-day-attacks-woocommerce-databases/167846/
Related news
- Critical PostgreSQL bug tied to zero-day attack on US Treasury (source)
- Apple fixes zero-day exploited in 'extremely sophisticated' attacks (source)
- Apple fixes zero-day flaw exploited in “extremely sophisticated” attack (CVE-2025-24200) (source)
- PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks (source)
- Microsoft fixes Power Pages zero-day bug exploited in attacks (source)
- Broadcom fixes three VMware zero-days exploited in attacks (source)
- CISA tags critical Ivanti EPM flaws as actively exploited in attacks (source)
- Critical PHP RCE vulnerability mass exploited in new attacks (source)
- Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks (source)
- Choose your own Patch Tuesday adventure: Start with six zero day fixes, or six critical flaws (source)