First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in origincode Product Catalog allows SQL Injection. This issue affects Product Catalog: from n/a through 1.0.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
origincode Product Catalog | <=1.0.4 | |
WordPress Product Catalog | <=1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30524 is classified as a high severity SQL Injection vulnerability.
To fix CVE-2025-30524, update the origincode Product Catalog plugin to the latest version beyond 1.0.4.
CVE-2025-30524 affects all versions of Product Catalog up to and including 1.0.4.
CVE-2025-30524 impacts both the origincode Product Catalog and WordPress Product Catalog.
No, using Product Catalog version 1.0.4 is unsafe due to the SQL Injection vulnerability identified by CVE-2025-30524.