Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows SQL Injection.This issue affects Actionwear products sync: from n/a through <= 2.3.3.
Published: 2025-04-01
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper neutralization of special elements used in an SQL command. The Actionwear products sync plugin allows an attacker to inject arbitrary SQL statements, potentially exposing sensitive data, modifying database contents, or providing further exploitability to the database level. No direct exploitation evidence is reported, but the impact could be significant if the injector can read or alter application data or credentials.

Affected Systems

All installations of the Actionwear products sync plugin from the initial release up through version 2.3.3 are affected. The vendor, marcoingraiti, has not identified a patch or further version details for the affected state beyond the limit of 2.3.3; therefore any site running any version up to and including 2.3.3 carries the risk.

Risk and Exploitability

The CVSS score of 8.5 classifies this flaw as high severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the current environment. The vulnerability is remotely reachable via web requests to the plugin’s endpoints, but it requires crafted input to trigger the injection. The lack of listing in CISA’s KEV catalog and the absence of publicly known exploits means that the attack vector is theoretical rather than demonstrated; however, the potential impact warrants prompt attention.

Generated by OpenCVE AI on May 1, 2026 at 01:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Actionwear products sync plugin to the latest version (≥ 2.3.4).
  • If an upgrade is not immediately possible, remove or disable the plugin entirely.
  • Implement strict input validation or filter on the plugin’s exposed endpoints to reject suspicious SQL payloads.
  • Deploy a Web Application Firewall rule that detects and blocks common SQL injection patterns sent to the plugin’s URLs.

Generated by OpenCVE AI on May 1, 2026 at 01:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9440 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync allows SQL Injection. This issue affects Actionwear products sync: from n/a through 2.3.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync allows SQL Injection. This issue affects Actionwear products sync: from n/a through 2.3.3. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows SQL Injection.This issue affects Actionwear products sync: from n/a through <= 2.3.3.
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Thu, 10 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 21:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync allows SQL Injection. This issue affects Actionwear products sync: from n/a through 2.3.3.
Title WordPress Actionwear products sync plugin <= 2.3.3 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Marcoingraiti Actionwear Products Sync
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:10.515Z

Reserved: 2025-03-31T10:06:23.643Z

Link: CVE-2025-31619

cve-icon Vulnrichment

Updated: 2025-04-10T14:31:13.636Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T21:15:51.690

Modified: 2026-04-23T15:28:05.357

Link: CVE-2025-31619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T01:30:05Z

Weaknesses