SQL Injection Vulnerability in GG Bought Together for WooCommerce by wpopal
CVE-2025-23967
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2025
What is CVE-2025-23967?
A vulnerabilities exists in the GG Bought Together for WooCommerce plugin by wpopal, where improper handling of special SQL elements can lead to SQL Injection attacks. Attackers can exploit this flaw to execute arbitrary SQL commands, potentially compromising database integrity and exposing sensitive data. This vulnerability affects versions from n/a up to 1.0.2, highlighting the need for immediate attention and patching to protect against potential exploits.
Affected Version(s)
GG Bought Together for WooCommerce <= 1.0.2