Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce wp-ticketbai allows Blind SQL Injection.This issue affects TicketBAI Facturas para WooCommerce: from n/a through <= 3.19.
Published: 2025-06-09
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a blind SQL injection flaw in the TicketBAI Facturas para WooCommerce plugin for WordPress due to improper neutralization of special characters in SQL statements. An attacker who can supply a crafted input to the plugin would be able to inject arbitrary SQL code, enabling blind extraction of data from the database. The description does not mention remote code execution or privilege escalation, so the impact is limited to data compromise.

Affected Systems

WordPress sites that have the TicketBAI Facturas para WooCommerce plugin installed in any version up to and including 3.19 are affected. The flaw applies uniformly across all installations of this plugin from its earliest release through the identified maximum version, regardless of other WordPress components or configurations.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity flaw that can compromise the confidentiality of site data. The EPSS score of < 1% shows that the probability of widespread exploitation is low, but the vulnerability remains a valid target for actors seeking to obtain sensitive data from a specific site. The flaw is not listed in the CISA KEV catalog. Attackers would need access to an endpoint of the plugin that receives user input; based on the description, it is inferred that the attack vector involves supplying a malicious payload to the plugin’s input handling. A successful exploitation would allow the attacker to extract information from the database, but it requires that the plugin’s endpoint is reachable and the attacker can deliver crafted HTTP requests.

Generated by OpenCVE AI on May 2, 2026 at 11:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TicketBAI Facturas para WooCommerce plugin to a version newer than 3.19 to remove the flaw.
  • If an upgrade is not possible, disable or uninstall the plugin to eliminate the vulnerable code from the site.
  • Implement or verify that any user‑input handling in the plugin uses parameterized queries or proper sanitization to prevent SQL injection.

Generated by OpenCVE AI on May 2, 2026 at 11:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17479 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce allows Blind SQL Injection. This issue affects TicketBAI Facturas para WooCommerce: from n/a through 3.19.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce allows Blind SQL Injection. This issue affects TicketBAI Facturas para WooCommerce: from n/a through 3.19. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce wp-ticketbai allows Blind SQL Injection.This issue affects TicketBAI Facturas para WooCommerce: from n/a through <= 3.19.
Title WordPress TicketBAI Facturas para WooCommerce <= 3.19 - SQL Injection Vulnerability WordPress TicketBAI Facturas para WooCommerce plugin <= 3.19 - SQL Injection Vulnerability
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00039}

epss

{'score': 0.00043}


Tue, 10 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce allows Blind SQL Injection. This issue affects TicketBAI Facturas para WooCommerce: from n/a through 3.19.
Title WordPress TicketBAI Facturas para WooCommerce <= 3.19 - SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:34.346Z

Reserved: 2025-01-23T14:53:16.439Z

Link: CVE-2025-24767

cve-icon Vulnrichment

Updated: 2025-06-10T13:31:37.214Z

cve-icon NVD

Status : Deferred

Published: 2025-06-09T16:15:35.047

Modified: 2026-06-17T08:59:34.483

Link: CVE-2025-24767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T11:15:19Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')