CVE-2025-22713: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-22713 is a SQL Injection vulnerability in the WooCommerce Orders & Customers Exporter WordPress plugin (slug: woocommerce-orders-ei) developed by vanquish. It affects all versions through 5.4 and was reported by researcher João Pedro S Alcântara (Kinorth) on August 20, 2025, with public disclosure on January 8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 score of 8.5 (High), requiring Subscriber-level privileges, while CISA-ADP initially scored it 9.8 (Critical) before that score was removed following Patchstack's revised assessment (Patchstack, NVD).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is incorporated into database queries without adequate sanitization or parameterization. Exploitation requires at minimum Subscriber-level authentication (a low-privilege WordPress role), and the attack is conducted over the network with low complexity and no user interaction required. The flaw resides within the plugin's export functionality, which processes user-controlled parameters that are passed unsafely to the underlying WordPress database layer, enabling an attacker to inject arbitrary SQL statements (Patchstack).

Impact

Successful exploitation allows an authenticated attacker with Subscriber-level access to execute arbitrary SQL commands against the WordPress/WooCommerce database. This can result in unauthorized disclosure of sensitive customer data (names, addresses, order history, payment metadata), modification or deletion of database records, and potential availability degradation. Given that WooCommerce stores e-commerce transaction data, the exposure risk to personally identifiable information (PII) and business-critical records is significant (Patchstack).

Exploitability

As of the time of disclosure, no public proof-of-concept exploit code has been identified and there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WooCommerce Orders & Customers Exporter plugin (version ≤ 5.4) using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files at /wp-content/plugins/woocommerce-orders-ei/readme.txt.
  2. Obtain low-privilege access: Register or obtain a Subscriber-level account on the target WordPress site (e.g., via open user registration, which is common on WooCommerce stores).
  3. Authenticate: Log in to the WordPress site with the Subscriber account to obtain a valid session cookie or nonce.
  4. Identify vulnerable endpoint: Locate the plugin's export functionality endpoint (typically accessible via the WordPress admin or a front-end export trigger associated with the plugin).
  5. Inject SQL payload: Craft a malicious HTTP request to the vulnerable parameter within the plugin's export functionality, injecting SQL syntax (e.g., UNION SELECT or time-based blind injection payloads) to extract data from the database.
  6. Exfiltrate data: Use the SQL injection to enumerate tables, extract WordPress user credentials (wp_users), WooCommerce order data, and customer PII from the database (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to the plugin's export endpoint containing SQL metacharacters (e.g., ', --, UNION, SELECT, SLEEP, BENCHMARK) in query parameters; repeated requests from a single IP to the export functionality.
  • Logs: WordPress/Apache/Nginx access logs showing abnormal parameter values in requests to plugin-related URLs (e.g., paths containing woocommerce-orders-ei); database error messages logged in wp-content/debug.log related to malformed SQL queries.
  • Database: Unexpected queries in MySQL general query log involving UNION SELECT or time-delay functions (SLEEP(), BENCHMARK()) originating from the WordPress database user; unauthorized reads of wp_users or sensitive WooCommerce tables.
  • Process: Unusual outbound connections from the web server process if the SQL injection is leveraged for out-of-band data exfiltration (e.g., DNS or HTTP-based exfil via LOAD_FILE or INTO OUTFILE).

Mitigation and workarounds

As of the disclosure date, no official patch has been released by the plugin developer for versions through 5.4. Site administrators should consider temporarily disabling or removing the WooCommerce Orders & Customers Exporter plugin until a patched version is available. Patchstack has issued a virtual patching/mitigation rule for subscribers of its service to block exploitation attempts. Additional mitigations include deploying a Web Application Firewall (WAF) with SQL injection detection rules, enabling WordPress debug logging to monitor for anomalous database activity, and restricting user registration to prevent unauthorized Subscriber account creation (Patchstack).

Community reactions

The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for January 5–11, 2026, highlighting it among notable plugin vulnerabilities of that period (Wordfence Blog). It was also noted on security-focused social media accounts including TheHackerWire on Mastodon and Infosec.Exchange shortly after disclosure. No significant vendor statements or major media coverage beyond standard vulnerability reporting have been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management