CVE-2025-47538

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce allows SQL Injection. This issue affects Cart tracking for WooCommerce: from n/a through 1.0.17.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpdever:cart_tracking_for_woocommerce:*:*:*:*:*:wordpress:*:*

History

09 Jun 2025, 17:02

Type Values Removed Values Added
CPE cpe:2.3:a:wpdever:cart_tracking_for_woocommerce:*:*:*:*:*:wordpress:*:*
References () https://patchstack.com/database/wordpress/plugin/cart-tracking-for-woocommerce/vulnerability/wordpress-cart-tracking-for-woocommerce-1-0-17-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/cart-tracking-for-woocommerce/vulnerability/wordpress-cart-tracking-for-woocommerce-1-0-17-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
First Time Wpdever cart Tracking For Woocommerce
Wpdever

08 May 2025, 14:39

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en wpdever Cart tracking for WooCommerce permite la inyección SQL. Este problema afecta al seguimiento de carritos de WooCommerce desde n/d hasta la versión 1.0.17.

07 May 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 15:16

Updated : 2025-06-09 17:02


NVD link : CVE-2025-47538

Mitre link : CVE-2025-47538

CVE.ORG link : CVE-2025-47538


JSON object : View

Products Affected

wpdever

  • cart_tracking_for_woocommerce
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')