SQL Injection Vulnerability in LETSCMS MLM Software Binary MLM Plan
CVE-2025-47671

7.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 May 2025

What is CVE-2025-47671?

The LETSCMS MLM Software Binary MLM Plan contains a vulnerability that permits SQL Injection attacks, allowing malicious users to manipulate SQL queries to execute arbitrary commands. This vulnerability impacts versions from n/a to 3.0, posing significant risks to data integrity and security. Effective measures should be taken to update and secure the software to mitigate potential threats.

Affected Version(s)

Binary MLM Plan <= 3.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

astra.r3verii (Patchstack Alliance)
.