PT-2025-47974 · Unknown+1 · Woocommerce+1

Published

2025-11-24

·

Updated

2025-11-25

·

CVE-2025-10144

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Perfect Brands for WooCommerce plugin for WordPress versions through 3.6.2
Description The Perfect Brands for WooCommerce plugin for WordPress is susceptible to time-based SQL Injection through the brands attribute of the products shortcode. Insufficient escaping of user-supplied parameters and inadequate preparation of existing SQL queries contribute to this issue. Authenticated attackers with Contributor-level access or higher can append additional SQL queries to existing ones, potentially extracting sensitive information from the database.
Recommendations Update The Perfect Brands for WooCommerce plugin to a version later than 3.6.2.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10144

Affected Products

Perfect Brands For Woocommerce
Woocommerce