CVE-2025-58788: WordPress License Manager for WooCommerce Plugin <= 3.0.12 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce allows Blind SQL Injection. This issue affects License Manager for WooCommerce: from n/a through 3.0.12.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58788?
CVE-2025-58788 is classified as a high severity SQL Injection vulnerability.
How do I fix CVE-2025-58788?
To fix CVE-2025-58788, update the Saad Iqbal License Manager for WooCommerce to the latest version beyond 3.0.12.
What platforms are affected by CVE-2025-58788?
CVE-2025-58788 affects the License Manager for WooCommerce plugin versions up to 3.0.12.
What type of attack does CVE-2025-58788 allow?
CVE-2025-58788 allows for Blind SQL Injection attacks due to improper input handling.
Can CVE-2025-58788 lead to data leakage?
Yes, CVE-2025-58788 can potentially lead to unauthorized access to sensitive data stored in the database.