First published: Sat Mar 15 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce allows SQL Injection. This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Multiple Shipping And Billing Address For WooCommerce | <=1.3 | |
SilverPlugins Multiple Shipping And Billing Address For Woocommerce | <=1.3 |
Update the WordPress Multiple Shipping And Billing Address For Woocommerce wordpress plugin to the latest available version (at least 1.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26875 has been classified as a high-severity vulnerability due to its potential for SQL Injection attacks.
To mitigate CVE-2025-26875, update the Multiple Shipping And Billing Address For Woocommerce plugin to the latest version provided by SilverPlugins.
CVE-2025-26875 can allow attackers to execute arbitrary SQL commands on your database, compromising sensitive data.
Yes, CVE-2025-26875 can be exploited relatively easily if the vulnerable plugin is used without protective measures.
CVE-2025-26875 affects Multiple Shipping And Billing Address For Woocommerce versions up to and including 1.3.