First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shopperdotcom Shopper allows SQL Injection. This issue affects Shopper: from n/a through 3.2.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
shopperdotcom Shopper | <=3.2.5 | |
WordPress Shopper plugin | <=3.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-31534 is classified as high due to its SQL injection capabilities.
To fix CVE-2025-31534, upgrade the Shopper or WordPress Shopper plugin to the latest version that is not affected.
CVE-2025-31534 affects Shopperdotcom Shopper versions up to 3.2.5 and the WordPress Shopper plugin up to version 3.2.5.
CVE-2025-31534 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Yes, CVE-2025-31534 can be exploited remotely by attackers if they can send malicious SQL commands to the affected applications.