cleantalk
Vulnerabilities and Security Researches

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light, CVE-2025-48122

CVE, Research URL

CVE-2025-48122

Published on
Jun 09, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows SQL Injection. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4.37.
Affected versions
Min -, max 2.4.37.
Status
vulnerable