SQL Injection Vulnerability in FluentCart Plugin for WordPress
CVE-2025-13495

4.9MEDIUM

What is CVE-2025-13495?

The FluentCart plugin for WordPress has a vulnerability that allows customized SQL queries via the 'groupKey' parameter due to improper parameter handling. Authenticated users with Administrator-level access can exploit this flaw to execute arbitrary SQL commands that may reveal sensitive database information. This issue stems from inadequate input validation, making it critical for site administrators to upgrade to versions beyond 1.3.1 to mitigate the risks associated with this vulnerability.

Affected Version(s)

FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler 0 <= 1.3.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Itthidej Aramsri
.