CVE-2025-22639: WordPress Distance Rate Shipping for WooCommerce plugin <= 1.3.4 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerce distance-rate-shipping-for-woocommerce-pro allows Blind SQL Injection.This issue affects Distance Rate Shipping for WooCommerce: from n/a through <= 1.3.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22639?
CVE-2025-22639 has a high severity due to the potential for Blind SQL Injection, which can lead to unauthorized database access.
How do I fix CVE-2025-22639?
To fix CVE-2025-22639, update the Distance Rate Shipping for WooCommerce plugin to the latest version that addresses the vulnerability.
What systems are affected by CVE-2025-22639?
CVE-2025-22639 affects Distance Rate Shipping for WooCommerce versions up to and including 1.3.4.
Can CVE-2025-22639 lead to data exposure?
Yes, CVE-2025-22639 can lead to data exposure through Blind SQL Injection, allowing attackers to manipulate the database.
Is CVE-2025-22639 specific to any platform?
CVE-2025-22639 is specifically related to the WordPress platform and its Distance Rate Shipping for WooCommerce plugin.