cleantalk
Vulnerabilities and Security Researches

YayExtra – WooCommerce Extra Product Options, CVE-2025-48299

CVE, Research URL

CVE-2025-48299

Published on
Jul 16, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra allows SQL Injection. This issue affects YayExtra: from n/a through 1.5.5.
Affected versions
Min -, max 1.5.6.
Status
vulnerable