PT-2025-50901 · Unknown+1 · Woocommerce+1

Marcin Dudek

·

Published

2025-12-12

·

Updated

2025-12-17

·

CVE-2025-14169

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress versions through 3.13.1.5
Description The software is susceptible to a time-based blind SQL Injection issue via the opid parameter. This is due to inadequate input sanitization and insufficient query preparation. An unauthenticated attacker can inject additional SQL queries into existing database queries, potentially extracting sensitive information.
Recommendations Versions prior to 3.13.1.5 should be updated.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-14169

Affected Products

Funnelkit
Woocommerce