CVE-2025-31599: WordPress Bulk Product Sync plugin <= 8.6 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync allows SQL Injection. This issue affects Bulk Product Sync: from n/a through 8.6.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync sync-wc-google allows SQL Injection.This issue affects Bulk Product Sync: from n/a through <= 8.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31599?
CVE-2025-31599 has a high severity due to its potential for SQL Injection attacks, which can lead to unauthorized data exposure and manipulation.
How do I fix CVE-2025-31599?
To fix CVE-2025-31599, update N-Media Bulk Product Sync to a version newer than 8.6 or apply any available security patches.
What are the consequences of exploiting CVE-2025-31599?
Exploiting CVE-2025-31599 can lead to unauthorized access to the database, data loss, and potential compromise of the entire application.
Which versions are affected by CVE-2025-31599?
CVE-2025-31599 affects all versions of N-Media Bulk Product Sync up to and including 8.6.
Is there any workaround for CVE-2025-31599?
Currently, the best workaround for CVE-2025-31599 is to restrict database access and monitor for unusual activity until a patch can be applied.