SQL Injection Vulnerability in WC Vendors Marketplace by WCVendors
CVE-2025-49263
7.6HIGH
What is CVE-2025-49263?
An SQL Injection vulnerability in the WC Vendors Marketplace plugin allows attackers to execute unauthorized SQL commands against the application's database. This can lead to unauthorized data access or manipulation without proper user authentication or authorization. The issue affects versions prior to 2.5.6, making it crucial for users to update their installations to mitigate security risks.
Affected Version(s)
WC Vendors Marketplace <= 2.5.6