CVE-2025-48299: WordPress YayExtra plugin <= 1.5.5 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra allows SQL Injection. This issue affects YayExtra: from n/a through 1.5.5.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra yayextra allows SQL Injection.This issue affects YayExtra: from n/a through <= 1.5.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48299?
CVE-2025-48299 is considered a critical SQL Injection vulnerability that can compromise database integrity.
How do I fix CVE-2025-48299?
To fix CVE-2025-48299, update YayExtra to version 1.5.6 or later immediately.
Who is affected by CVE-2025-48299?
CVE-2025-48299 affects YayCommerce YayExtra versions up to and including 1.5.5.
What kind of attacks can be executed through CVE-2025-48299?
CVE-2025-48299 allows attackers to perform SQL Injection attacks, potentially leading to unauthorized access to sensitive data.
What products are impacted by CVE-2025-48299?
CVE-2025-48299 impacts both YayCommerce YayExtra and WordPress YayExtra up to version 1.5.5.