CVE-2025-22713

9.8

vanquish · WooCommerce Orders & Customers Exporter

The WooCommerce Orders & Customers Exporter plugin for WordPress contains an SQL injection vulnerability that allows authenticated users to execute malicious database queries.

Executive summary

An SQL injection vulnerability in the WooCommerce Orders & Customers Exporter plugin poses a risk of unauthorized database access to authenticated users.

Vulnerability

This vulnerability is an Improper Neutralization of Special Elements used in an SQL Command (CWE-89). It allows an authenticated user to perform SQL injection attacks, potentially compromising database integrity.

Business impact

The ability to perform SQL injection allows attackers to bypass standard application logic to access or modify sensitive data. With a CVSS score of 9.8, this flaw represents a significant risk to the integrity and confidentiality of customer and order data stored in the WooCommerce environment.

Remediation

Immediate Action: No patch is currently available; users are advised to deactivate the plugin until the vendor issues a fix to remediate the SQL injection flaw.

Proactive Monitoring: Regularly audit database logs for anomalies and monitor user activity for signs of unauthorized data retrieval or administrative query execution.

Compensating Controls: Implement WAF rules specifically designed to detect and block SQL injection payloads at the application edge to provide a layer of protection while the plugin remains inactive.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of the vulnerability and the lack of a current patch, immediate deactivation of the WooCommerce Orders & Customers Exporter plugin is the only effective way to prevent exploitation. Security administrators should maintain vigilance and apply updates immediately upon the vendor's release of a verified fix.