SQL Injection Vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting
CVE-2025-31553
9.3CRITICAL
What is CVE-2025-31553?
A vulnerability in WPFactory's Advanced WooCommerce Product Sales Reporting plugin allows an attacker to execute unauthorized SQL commands. This SQL injection flaw can lead to significant data exposure or corruption by manipulating database queries. Affected versions include all prior to 3.1. It is crucial for users of this plugin to review their security measures and apply necessary updates to mitigate potential risks.
Affected Version(s)
Advanced WooCommerce Product Sales Reporting <= 3.1
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published