CVE-2025-31553: WordPress Advanced WooCommerce Product Sales Reporting plugin <= 4.1.1 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31553?
The severity of CVE-2025-31553 is classified as critical due to its potential to allow SQL injection attacks.
How do I fix CVE-2025-31553?
To fix CVE-2025-31553, you should update the Advanced WooCommerce Product Sales Reporting plugin to version 3.2 or later.
What software is affected by CVE-2025-31553?
CVE-2025-31553 affects the Advanced WooCommerce Product Sales Reporting plugin versions up to and including 3.1.
What type of vulnerability is CVE-2025-31553?
CVE-2025-31553 is an SQL injection vulnerability caused by improper neutralization of special elements in SQL commands.
Which vendors are connected to CVE-2025-31553?
CVE-2025-31553 is associated with the vendors WPFactory and WordPress.