First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trust Payments Trust Payments Gateway for WooCommerce allows SQL Injection. This issue affects Trust Payments Gateway for WooCommerce: from n/a through 1.1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Trust Payments Gateway for WooCommerce | <=1.1.4 | |
Trust Payments Gateway for WooCommerce | <=1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28942 is classified as a high severity SQL Injection vulnerability affecting versions of Trust Payments Gateway for WooCommerce up to 1.1.4.
To fix CVE-2025-28942, upgrade Trust Payments Gateway for WooCommerce to the latest version that resolves this SQL Injection vulnerability.
The potential impacts of CVE-2025-28942 include unauthorized access to the database, data manipulation, and potential system compromise.
CVE-2025-28942 affects all versions of Trust Payments Gateway for WooCommerce from n/a through 1.1.4.
Yes, there are known exploitation methods for CVE-2025-28942 that can be used to carry out SQL Injection attacks against affected versions.