First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync allows SQL Injection. This issue affects Actionwear products sync: from n/a through 2.3.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Actionwear products sync | <=2.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31619 is classified as a critical SQL Injection vulnerability affecting Actionwear products sync.
To fix CVE-2025-31619, update the Actionwear products sync plugin to version 2.3.4 or later.
CVE-2025-31619 affects versions of WordPress Actionwear products sync from n/a up to 2.3.3.
CVE-2025-31619 is an SQL Injection vulnerability that allows for improper neutralization of special elements in SQL commands.
Users of the Actionwear products sync plugin for WordPress running versions 2.3.3 or earlier are impacted by CVE-2025-31619.