CVE-2025-2203: WooCommerce Checkout & Funnel Builder by FunnelKit < 3.10.2 - Admin+ SQL Injection
Published May 15, 2025
·Updated
The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
2 affected components
FunnelKit FunnelKit WordPress plugin<3.10.2
FunnelKit Funnel Builder Wordpress<3.10.2
Event History
May 15, 2025
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-2203?
CVE-2025-2203 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2025-2203?
To fix CVE-2025-2203, update the FunnelKit WordPress plugin to version 3.10.2 or later.
3
What is the impact of CVE-2025-2203?
CVE-2025-2203 allows attackers to execute arbitrary SQL queries, which can compromise the database and sensitive data.
4
Who is affected by CVE-2025-2203?
CVE-2025-2203 affects all versions of the FunnelKit WordPress plugin prior to version 3.10.2.
5
Can CVE-2025-2203 be exploited remotely?
Yes, CVE-2025-2203 can be exploited remotely by an attacker with admin access to the affected WordPress site.