Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerce distance-rate-shipping-for-woocommerce-pro allows Blind SQL Injection.This issue affects Distance Rate Shipping for WooCommerce: from n/a through <= 1.3.4.
Published: 2025-02-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in the WordPress Distance Rate Shipping for WooCommerce plugin up to version 1.3.4 and results from improper neutralization of special characters in SQL statements. The flaw permits blind SQL injection. Based on the description, it is inferred that an attacker could send specially crafted input that is incorporated into database queries, potentially enabling unauthorized access to or alteration of database data. This would jeopardize the confidentiality and integrity of the e‑commerce platform.

Affected Systems

The vulnerability affects installations of the Techspawn Distance Rate Shipping for WooCommerce plugin, specifically versions n/a through 1.3.4. Any WordPress site running WooCommerce with one of these plugin versions is susceptible, regardless of the hosting environment or network configuration.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, while the EPSS of < 1% suggests a low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through web requests that submit shipping parameters, with the attacker crafting specially encoded values that are incorporated directly into database queries. Successful exploitation would require an attacker to have network access to the web application.

Generated by OpenCVE AI on May 2, 2026 at 04:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Distance Rate Shipping for WooCommerce plugin to the latest available version that contains the fix.
  • If an upgrade is not immediately possible, limit access to the plugin’s configuration pages to authenticated administrators only and monitor for suspicious activity.
  • Implement SQL injection protection by applying a web application firewall that blocks payloads containing common SQL keywords and patterns.

Generated by OpenCVE AI on May 2, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4785 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Distance Rate Shipping for WooCommerce allows Blind SQL Injection. This issue affects Distance Rate Shipping for WooCommerce: from n/a through 1.3.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Distance Rate Shipping for WooCommerce allows Blind SQL Injection. This issue affects Distance Rate Shipping for WooCommerce: from n/a through 1.3.4. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerce distance-rate-shipping-for-woocommerce-pro allows Blind SQL Injection.This issue affects Distance Rate Shipping for WooCommerce: from n/a through <= 1.3.4.
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Tue, 18 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Feb 2025 20:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Distance Rate Shipping for WooCommerce allows Blind SQL Injection. This issue affects Distance Rate Shipping for WooCommerce: from n/a through 1.3.4.
Title WordPress Distance Rate Shipping for WooCommerce plugin <= 1.3.4 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:02.859Z

Reserved: 2025-01-07T21:02:36.080Z

Link: CVE-2025-22639

cve-icon Vulnrichment

Updated: 2025-02-18T20:21:49.255Z

cve-icon NVD

Status : Deferred

Published: 2025-02-18T20:15:26.010

Modified: 2026-04-23T15:23:18.533

Link: CVE-2025-22639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:30:16Z

Weaknesses