SQL Injection Vulnerability in Persian Woocommerce SMS by PersianScript
CVE-2025-49315

7.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-49315?

An SQL Injection vulnerability exists in the Persian Woocommerce SMS plugin developed by PersianScript, particularly in versions up to 7.0.10. This flaw allows unauthorized users to execute arbitrary SQL code, potentially compromising the database and leading to data exposure. Application developers are urged to address this issue promptly to prevent security breaches. Users should ensure that they are using the latest version of the plugin to mitigate risks.

Affected Version(s)

Persian Woocommerce SMS <= 7.0.10

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martino Spagnuolo (r3verii) (Patchstack Alliance)
.
CVE-2025-49315 : SQL Injection Vulnerability in Persian Woocommerce SMS by PersianScript