PT-2025-36366 · WordPress · Elex Woocommerce Google Shopping Plugin

Đức Tài

·

Published

2025-09-06

·

Updated

2025-09-07

·

CVE-2025-10046

CVSS v3.1
4.9
VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

ELEX WooCommerce Google Shopping plugin for WordPress versions up to and including 1.4.3

Description:

The ELEX WooCommerce Google Shopping plugin for WordPress is susceptible to SQL Injection through the `file to delete` parameter. Insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries allow authenticated attackers with Administrator-level access or higher to inject additional SQL queries. This can lead to the extraction of sensitive information from the database.

Recommendations:

Update ELEX WooCommerce Google Shopping plugin to a version later than 1.4.3.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10046

Affected Products

Elex Woocommerce Google Shopping Plugin