PT-2025-38974 · Woocommerce · Perfect Brands For Woocommerce

Published

2025-09-22

·

Updated

2025-09-24

·

CVE-2025-58686

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Perfect Brands for WooCommerce versions through 3.6.0
Description A flaw exists in Perfect Brands for WooCommerce that allows for SQL Injection. This occurs due to improper neutralization of special elements within SQL commands. The issue enables attackers to exploit SQL commands by injecting malicious code.
Recommendations Update Perfect Brands for WooCommerce to a version later than 3.6.0.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-58686

Affected Products

Perfect Brands For Woocommerce