Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2.
Published: 2025-05-07
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special characters used in an SQL command allows an attacker to inject arbitrary SQL statements. This flaw falls under CWE-89 and can result in data exfiltration, modification, or deletion if exploited. The vulnerability exists in the "ELEX Product Feed for WooCommerce" plugin and allows attackers to manipulate database queries, potentially compromising the entire WordPress site. The impact is a loss of data confidentiality, integrity, and availability for affected users.

Affected Systems

ELEXtensions’ "ELEX Product Feed for WooCommerce" plugin, versions from the earliest available releases through 3.1.2, is vulnerable. All WordPress installations utilizing these plugin versions are at risk, regardless of other security controls in place.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity flaw. The EPSS score of less than 1% suggests that it is unlikely to be widely exploited currently, and the lack of listing in the CISA KEV catalog confirms no public exploitation reports at this time. Likely attack vectors involve remote exploitation through crafted HTTP requests to the plugin’s feed generation endpoints, as the plugin accepts user‑supplied input without proper sanitization. An attacker with sufficient access to submit such requests can execute SQL queries against the database.

Generated by OpenCVE AI on April 30, 2026 at 13:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest plugin update (any release beyond 3.1.2) to eliminate the flaw.
  • Restrict access to the feed‑generation functionality so that only privileged users can invoke it.
  • If an immediate update is not possible, implement input sanitization or temporarily disable the plugin’s feed feature until a patch is applied.

Generated by OpenCVE AI on April 30, 2026 at 13:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13747 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce elex-product-feed allows SQL Injection.This issue affects ELEX Product Feed for WooCommerce: from n/a through <= 3.1.2. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2.
Title WordPress ELEX Product Feed for WooCommerce plugin <= 3.1.2 - SQL Injection Vulnerability WordPress ELEX Product Feed for WooCommerce <= 3.1.2 - SQL Injection Vulnerability
References

Thu, 23 Apr 2026 15:45:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce elex-product-feed allows SQL Injection.This issue affects ELEX Product Feed for WooCommerce: from n/a through <= 3.1.2.
Title WordPress ELEX Product Feed for WooCommerce <= 3.1.2 - SQL Injection Vulnerability WordPress ELEX Product Feed for WooCommerce plugin <= 3.1.2 - SQL Injection Vulnerability
References

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00039}

epss

{'score': 0.00041}


Wed, 07 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2.
Title WordPress ELEX Product Feed for WooCommerce <= 3.1.2 - SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:47.950Z

Reserved: 2025-05-07T10:45:05.653Z

Link: CVE-2025-47643

cve-icon Vulnrichment

Updated: 2025-05-07T20:40:50.956Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:17.193

Modified: 2026-04-28T19:32:30.453

Link: CVE-2025-47643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T13:15:37Z

Weaknesses