CVE-2025-47569: WordPress WooCommerce Ultimate Gift Card plugin <= 2.9.6 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates. This issue affects WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates: from n/a through 2.8.10.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Blind SQL Injection.This issue affects WooCommerce Ultimate Gift Card: from n/a through <= 2.9.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47569?
CVE-2025-47569 has been rated as a high severity SQL Injection vulnerability.
How do I fix CVE-2025-47569?
To fix CVE-2025-47569, update the WPSwings WooCommerce Ultimate Gift Card plugin to version 2.8.11 or later.
What are the potential impacts of CVE-2025-47569?
CVE-2025-47569 can allow an attacker to execute arbitrary SQL queries in the application's database.
Which versions of the WPSwings WooCommerce Ultimate Gift Card are affected by CVE-2025-47569?
CVE-2025-47569 affects WPSwings WooCommerce Ultimate Gift Card versions up to and including 2.8.10.
Is there a patch available for CVE-2025-47569?
Yes, a patch is available by upgrading to the latest version of the plugin that addresses CVE-2025-47569.