PT-2025-36761 · WordPress · Woocommerce Ultimate Gift Card

Bonds

·

Published

2025-09-09

·

Updated

2025-09-10

·

CVE-2025-47569

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions: WPSwings WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates versions through 2.8.10
Description: The software contains an SQL injection flaw that allows attackers to manipulate commands. This issue is due to improper neutralization of special elements used in an SQL command.
Recommendations: Update WPSwings WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates to a version later than 2.8.10.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-47569

Affected Products

Woocommerce Ultimate Gift Card