CVE-2025-47640: WordPress Printcart Web to Print Product Designer for WooCommerce plugin <= 2.4.0 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows SQL Injection. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.3.8.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47640?
CVE-2025-47640 has a critical severity level due to its potential for SQL Injection attacks.
How do I fix CVE-2025-47640?
To fix CVE-2025-47640, update the Printcart Web to Print Product Designer for WooCommerce to version 2.3.9 or later.
What types of attacks can CVE-2025-47640 allow?
CVE-2025-47640 can allow attackers to execute arbitrary SQL commands on the database.
Which versions of Printcart Web to Print Product Designer for WooCommerce are affected by CVE-2025-47640?
Versions up to and including 2.3.8 of Printcart Web to Print Product Designer for WooCommerce are affected by CVE-2025-47640.
Why is CVE-2025-47640 important to address?
CVE-2025-47640 is important to address because it can lead to unauthorized access and manipulation of sensitive database information.