First published: Wed May 07 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce allows Blind SQL Injection. This issue affects Dynamic Pricing With Discount Rules for WooCommerce: from n/a through 4.5.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
acowebs Dynamic Pricing With Discount Rules for WooCommerce | <=4.5.8 | |
WordPress Dynamic Pricing With Discount Rules for WooCommerce | <=4.5.8 |
Update the WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin to the latest available version (at least 4.5.9).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47544 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2025-47544, upgrade Dynamic Pricing With Discount Rules for WooCommerce to version 4.5.9 or later.
CVE-2025-47544 is an SQL injection vulnerability that allows for blind SQL injection attacks.
CVE-2025-47544 affects versions of Dynamic Pricing With Discount Rules for WooCommerce from n/a up to 4.5.8.
The vendor for the vulnerable software is Acowebs, and it is also associated with WordPress.