SQL Injection Vulnerability in Persian Woocommerce SMS by PersianScript
CVE-2025-49315
7.6HIGH
What is CVE-2025-49315?
An SQL Injection vulnerability exists in the Persian Woocommerce SMS plugin developed by PersianScript, particularly in versions up to 7.0.10. This flaw allows unauthorized users to execute arbitrary SQL code, potentially compromising the database and leading to data exposure. Application developers are urged to address this issue promptly to prevent security breaches. Users should ensure that they are using the latest version of the plugin to mitigate risks.
Affected Version(s)
Persian Woocommerce SMS <= 7.0.10