CVE-2025-24767 PUBLISHED

WordPress TicketBAI Facturas para WooCommerce <= 3.19 - SQL Injection Vulnerability

Assigner: Patchstack
Reserved: 23.01.2025 Published: 09.06.2025 Updated: 10.06.2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce allows Blind SQL Injection. This issue affects TicketBAI Facturas para WooCommerce: from n/a through 3.19.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
CVSS Score: 9.3

Product Status

Vendor facturaone
Product TicketBAI Facturas para WooCommerce
Versions Default: unaffected
  • affected from n/a to 3.19 (incl.)

Credits

  • Martino Spagnuolo (r3verii) (Patchstack Alliance) finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-7 Blind SQL Injection