Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through <= 3.1.
Published: 2025-12-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special elements in SQL statements allows an attacker to inject arbitrary SQL through the Advance Seat Reservation Management for WooCommerce plugin. The flaw, identified as CWE‑89, can lead to unauthorized data exposure, modification, and potentially the execution of arbitrary commands if database permissions are permissive. The vulnerability is present in all releases up to and including version 3.1.

Affected Systems

The affected product is the WordPress plugin Advance Seat Reservation Management for WooCommerce (scw‑seat‑reservation) from smartcms. All installations using version 3.1 or earlier are impacted. No specific patch version is listed, so the issue applies broadly to this release line.

Risk and Exploitability

The CVSS score of 9.3 places the flaw in the high‑severity range. The EPSS score of less than 1% indicates a low probability of exploitation in the current threat environment, and the vulnerability is not yet recorded in the CISA KEV catalog. The likely attack vector is through user-supplied input in the reservation or booking functionality, which may be accessible to authenticated or unauthenticated users depending on the site configuration. Proper input validation or parameterized queries would mitigate the risk, but an attacker could feasibly submit malicious payloads to the plugin’s database queries.

Generated by OpenCVE AI on April 29, 2026 at 22:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Advance Seat Reservation Management for WooCommerce plugin to the latest released version that removes the SQL injection flaw.
  • If upgrading is not immediately possible, disable the reservation functionality or the entire plugin until a patch is applied.
  • Sanitize all input that the plugin passes to database queries, ensuring the use of prepared statements or parameterized queries.
  • Deploy a web application firewall rule set that detects common SQL injection patterns targeting the plugin’s endpoints.

Generated by OpenCVE AI on April 29, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Smartcmsmarket
Smartcmsmarket advance Seat Reservation Management For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Smartcmsmarket
Smartcmsmarket advance Seat Reservation Management For Woocommerce
Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through <= 3.1.
Title WordPress Advance Seat Reservation Management for WooCommerce plugin <= 3.1 - SQL Injection vulnerability
Weaknesses CWE-89
References

Subscriptions

Smartcmsmarket Advance Seat Reservation Management For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:50.356Z

Reserved: 2025-09-06T04:44:54.906Z

Link: CVE-2025-58951

cve-icon Vulnrichment

Updated: 2025-12-18T16:15:09.352Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:03.030

Modified: 2026-04-27T20:16:22.443

Link: CVE-2025-58951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:30:21Z

Weaknesses