SQL Injection Vulnerability in WooBeWoo Product Filter Pro by WBW
CVE-2025-39496

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 August 2025

What is CVE-2025-39496?

The vulnerability exposes WooBeWoo Product Filter Pro to SQL injection attacks, allowing an attacker to manipulate SQL queries through improper neutralization of special elements. This can lead to unauthorized access to sensitive data and potentially compromise the security of affected websites. Users should ensure their installations are updated to version 2.9.6 or higher to mitigate this risk.

Affected Version(s)

WooBeWoo Product Filter Pro < 2.9.6

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc / truonghuuphuc (Patchstack Bug Bounty program)
.