SQL Injection Vulnerability in GG Bought Together for WooCommerce by wpopal
CVE-2025-23967

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 June 2025

What is CVE-2025-23967?

A vulnerabilities exists in the GG Bought Together for WooCommerce plugin by wpopal, where improper handling of special SQL elements can lead to SQL Injection attacks. Attackers can exploit this flaw to execute arbitrary SQL commands, potentially compromising database integrity and exposing sensitive data. This vulnerability affects versions from n/a up to 1.0.2, highlighting the need for immediate attention and patching to protect against potential exploits.

Affected Version(s)

GG Bought Together for WooCommerce <= 1.0.2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ch4r0n (Patchstack Alliance)
.