First published: Wed May 07 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds Productive Commerce allows SQL Injection. This issue affects Productive Commerce: from n/a through 1.1.22.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Productive Commerce | <=1.1.22 | |
Productive Minds Productive Commerce | <=1.1.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47657 has a high severity due to the risk of SQL Injection allowing attackers to manipulate database queries.
To fix CVE-2025-47657, update Productive Commerce to a version later than 1.1.22 where the vulnerability is resolved.
CVE-2025-47657 can enable attackers to execute arbitrary SQL commands, potentially exposing sensitive data and compromising the application.
CVE-2025-47657 affects Productive Commerce versions up to and including 1.1.22.
Users of Productive Minds Productive Commerce and WordPress Productive Commerce versions up to 1.1.22 are affected by CVE-2025-47657.