Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce woo-altcoin-payment-gateway allows Blind SQL Injection.This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through <= 1.7.6.
Published: 2025-03-03
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce plugin where user input is not properly neutralized before being embedded in an SQL command. Exploitation allows an attacker to inject SQL fragments into the plugin’s database queries, enabling read, update, or delete operations on data stored in the WordPress database. This can lead to the exfiltration of sensitive information or the alteration of transaction records. The flaw is a classic blind SQL injection, meaning it relies on side‑channel responses rather than directly returning data in the HTTP response.

Affected Systems

WordPress installations that have the CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce plugin installed at a version of 1.7.6 or earlier. The plugin is commonly used in multivendor stores and shops to process cryptocurrency payments.

Risk and Exploitability

With a CVSS score of 9.3 the flaw is considered critical, reflecting the high impact and wide availability of the attack. The EPSS score of less than 1% indicates that, as of the current analysis, observed exploitation attempts are rare, but the vulnerability still poses a significant risk if an attacker can craft a suitable HTTP request to the plugin’s endpoints. The attack is likely to occur through a remote, unauthenticated or minimally authenticated HTTP request that targets the plugin’s publicly exposed payment processing logic. Because the flaw is listed outside the KEV catalogue, it does not appear in the CISA Known Exploited Vulnerabilities list, yet it remains necessary to remediate it promptly to prevent potential data breaches.

Generated by OpenCVE AI on May 2, 2026 at 03:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce plugin to a version newer than 1.7.6 or apply any vendor‑supplied patch that addresses the blind SQL injection flaw.
  • If an upgrade or patch cannot be applied immediately, disable the plugin or remove it from the WordPress site until the vulnerability is fixed.
  • Configure the database user used by WordPress to have the least privileges necessary for the plugin, and monitor database logs for abnormal query patterns.
  • Deploy a web application firewall that inspects incoming requests for SQL injection signatures and blocks suspicious payloads targeting the plugin’s endpoints.

Generated by OpenCVE AI on May 2, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5631 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Bitcoin / AltCoin Payment Gateway for WooCommerce allows Blind SQL Injection. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through 1.7.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Bitcoin / AltCoin Payment Gateway for WooCommerce allows Blind SQL Injection. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through 1.7.6. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce woo-altcoin-payment-gateway allows Blind SQL Injection.This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through <= 1.7.6.
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Bitcoin / AltCoin Payment Gateway for WooCommerce allows Blind SQL Injection. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through 1.7.6.
Title WordPress Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop plugin <= 1.7.6 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:37.897Z

Reserved: 2025-02-12T13:58:16.935Z

Link: CVE-2025-26535

cve-icon Vulnrichment

Updated: 2025-03-03T15:48:31.631Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:54.900

Modified: 2026-06-17T09:01:59.077

Link: CVE-2025-26535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:00:13Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')