CVE-2025-22352
WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.8 - SQL Injection vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes allows Blind SQL Injection.This issue affects ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes: from n/a through 1.4.8.
Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices y Attributes permite la inyección SQL ciega. Este problema afecta a ELEX WooCommerce Advanced Bulk Edit Products, Prices y Attributes: desde n/a hasta 1.4.8.
The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-01-03 CVE Reserved
- 2025-01-03 CVE Published
- 2025-01-08 CVE Updated
- 2025-01-08 EPSS Updated
- 2025-01-08 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
- CAPEC-7: Blind SQL Injection
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Elex Bulk Edit Products Prices Attributes For Woocommerce Basic Search vendor "Elex Bulk Edit Products Prices Attributes For Woocommerce Basic" | Elex Bulk Edit Products Prices Attributes For Woocommerce Basic Search vendor "Elex Bulk Edit Products Prices Attributes For Woocommerce Basic" for product "Elex Bulk Edit Products Prices Attributes For Woocommerce Basic" | >= 0.0.0 <= 1.4.8 Search vendor "Elex Bulk Edit Products Prices Attributes For Woocommerce Basic" for product "Elex Bulk Edit Products Prices Attributes For Woocommerce Basic" and version " >= 0.0.0 <= 1.4.8" | en |
Affected
|