SQL Injection Vulnerability in ELEX WooCommerce Advanced Bulk Edit Plugin
CVE-2025-47645

8.5HIGH

What is CVE-2025-47645?

A vulnerability has been identified in the ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin, which allows an attacker to manipulate SQL queries due to inadequate neutralization of special SQL elements. This SQL injection vulnerability can lead to unauthorized data access and manipulation. The affected versions of the plugin are from an unspecified release up to 1.4.9. Administrators using these versions should take the necessary steps to secure their installations.

Affected Version(s)

ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.4.9

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martino Spagnuolo (r3verii) (Patchstack Alliance)
.
CVE-2025-47645 : SQL Injection Vulnerability in ELEX WooCommerce Advanced Bulk Edit Plugin