Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Payment Gateway Plugin hcv4-payment-gateway allows SQL Injection.This issue affects HieCOR Payment Gateway Plugin: from n/a through <= 1.5.11.
Published: 2025-11-06
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The HieCOR Payment Gateway Plugin contains an improper neutralization of special elements in SQL commands, allowing attackers to inject arbitrary SQL through the plugin’s input fields. Such injection could grant unauthorized data access or modification, compromising confidentiality, integrity, and availability of the WordPress site.

Affected Systems

WordPress sites running the HieCOR Payment Gateway Plugin version 1.5.11 or earlier are affected. All installations of this plugin at those versions are at risk.

Risk and Exploitability

With a CVSS score of 9.3 the flaw is critical. The EPSS score of less than 1% indicates that, while exploitation is possible, it is currently considered very unlikely in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely exploit the vulnerability through the plugin’s web interface on an exposed WordPress site, without needing prior authentication. The impact could lead to data exfiltration or further compromise of the database.

Generated by OpenCVE AI on April 30, 2026 at 14:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HieCOR Payment Gateway Plugin to version 1.5.12 or later, if a patch is available.
  • If an update cannot be applied immediately, remove or deactivate the plugin from the WordPress site entirely.
  • Implement input validation or deploy a web application firewall rule to block SQL injection payloads on the plugin’s exposed endpoints.

Generated by OpenCVE AI on April 30, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 10 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Payment Gateway Plugin hcv4-payment-gateway allows SQL Injection.This issue affects HieCOR Payment Gateway Plugin: from n/a through <= 1.5.11.
Title WordPress HieCOR Payment Gateway plugin plugin <= 1.5.11 - SQL Injection vulnerability
Weaknesses CWE-89
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:18.702Z

Reserved: 2025-06-19T10:03:09.016Z

Link: CVE-2025-52773

cve-icon Vulnrichment

Updated: 2025-11-10T19:31:38.946Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:15:54.933

Modified: 2026-04-27T17:16:27.473

Link: CVE-2025-52773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T14:45:24Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')