cleantalk
Vulnerabilities and Security Researches

Brands for WooCommerce, CVE-2025-68519

CVE, Research URL

CVE-2025-68519

Published on
Dec 24, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Blind SQL Injection.This issue affects Brands for WooCommerce: from n/a through <= 3.8.6.3.
Affected versions
max 3.8.6.4.
Status
vulnerable