CVE-2025-13495: FluentCart A New Era of eCommerce <= 1.3.1 - Authenticated (Administrator+) SQL Injection via 'groupKey' Parameter
The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, and including, 1.3.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13495?
CVE-2025-13495 is classified as a high severity vulnerability due to the potential for SQL Injection.
How do I fix CVE-2025-13495?
To fix CVE-2025-13495, upgrade the FluentCart plugin to version 1.3.2 or later.
What type of vulnerability is CVE-2025-13495?
CVE-2025-13495 is an SQL Injection vulnerability found in the FluentCart plugin for WordPress.
What versions of FluentCart are affected by CVE-2025-13495?
CVE-2025-13495 affects all versions of FluentCart up to and including version 1.3.1.
What causes the vulnerability CVE-2025-13495?
The vulnerability CVE-2025-13495 is caused by insufficient escaping of the 'groupKey' parameter in SQL queries.