
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-22713 is a SQL Injection vulnerability in the WooCommerce Orders & Customers Exporter WordPress plugin (slug: woocommerce-orders-ei) developed by vanquish. It affects all versions through 5.4 and was reported by researcher João Pedro S Alcântara (Kinorth) on August 20, 2025, with public disclosure on January 8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 score of 8.5 (High), requiring Subscriber-level privileges, while CISA-ADP initially scored it 9.8 (Critical) before that score was removed following Patchstack's revised assessment (Patchstack, NVD).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is incorporated into database queries without adequate sanitization or parameterization. Exploitation requires at minimum Subscriber-level authentication (a low-privilege WordPress role), and the attack is conducted over the network with low complexity and no user interaction required. The flaw resides within the plugin's export functionality, which processes user-controlled parameters that are passed unsafely to the underlying WordPress database layer, enabling an attacker to inject arbitrary SQL statements (Patchstack).
Successful exploitation allows an authenticated attacker with Subscriber-level access to execute arbitrary SQL commands against the WordPress/WooCommerce database. This can result in unauthorized disclosure of sensitive customer data (names, addresses, order history, payment metadata), modification or deletion of database records, and potential availability degradation. Given that WooCommerce stores e-commerce transaction data, the exposure risk to personally identifiable information (PII) and business-critical records is significant (Patchstack).
As of the time of disclosure, no public proof-of-concept exploit code has been identified and there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).
readme.txt files at /wp-content/plugins/woocommerce-orders-ei/readme.txt.UNION SELECT or time-based blind injection payloads) to extract data from the database.wp_users), WooCommerce order data, and customer PII from the database (Patchstack).', --, UNION, SELECT, SLEEP, BENCHMARK) in query parameters; repeated requests from a single IP to the export functionality.woocommerce-orders-ei); database error messages logged in wp-content/debug.log related to malformed SQL queries.UNION SELECT or time-delay functions (SLEEP(), BENCHMARK()) originating from the WordPress database user; unauthorized reads of wp_users or sensitive WooCommerce tables.LOAD_FILE or INTO OUTFILE).As of the disclosure date, no official patch has been released by the plugin developer for versions through 5.4. Site administrators should consider temporarily disabling or removing the WooCommerce Orders & Customers Exporter plugin until a patched version is available. Patchstack has issued a virtual patching/mitigation rule for subscribers of its service to block exploitation attempts. Additional mitigations include deploying a Web Application Firewall (WAF) with SQL injection detection rules, enabling WordPress debug logging to monitor for anomalous database activity, and restricting user registration to prevent unauthorized Subscriber account creation (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for January 5–11, 2026, highlighting it among notable plugin vulnerabilities of that period (Wordfence Blog). It was also noted on security-focused social media accounts including TheHackerWire on Mastodon and Infosec.Exchange shortly after disclosure. No significant vendor statements or major media coverage beyond standard vulnerability reporting have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."