CVE-2025-47608 PUBLISHED

WordPress Recover abandoned cart for WooCommerce <= 2.5 - SQL Injection Vulnerability

Assigner: Patchstack
Reserved: 07.05.2025 Published: 09.06.2025 Updated: 09.06.2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce allows SQL Injection. This issue affects Recover abandoned cart for WooCommerce: from n/a through 2.5.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
CVSS Score: 9.3

Product Status

Vendor sonalsinha21
Product Recover abandoned cart for WooCommerce
Versions Default: unaffected
  • affected from n/a to 2.5 (incl.)

Credits

  • ch4r0n (Patchstack Alliance) finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-66 SQL Injection