
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58951 is a SQL Injection vulnerability in the Advance Seat Reservation Management for WooCommerce WordPress plugin (slug: scw-seat-reservation) developed by smartcms. The flaw affects all versions up to and including 3.1, allowing unauthenticated remote attackers to inject malicious SQL commands via network access. It was published on December 18, 2025, and assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical) (Feedly, EUVD).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is incorporated into SQL queries without adequate sanitization or parameterization (Feedly). Because no authentication is required (privilegesRequired: NONE, userInteraction: NONE), an attacker can send crafted HTTP requests directly to vulnerable plugin endpoints over the network. The changed scope (S:C) in the CVSS vector indicates that a successful attack can impact resources beyond the plugin itself, such as the broader WordPress database. No public technical write-up or proof-of-concept code has been identified at this time (Feedly).
Successful exploitation could allow an unauthenticated attacker to read sensitive database contents (e.g., customer PII, order data, credentials), bypass authentication, modify or delete records, and potentially execute administrative database operations. The high confidentiality impact combined with changed scope means the entire WooCommerce site's data — including user accounts and payment-related information — is at risk. Availability is also partially affected, as database manipulation could disrupt site functionality (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.021%, reflecting a currently low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the unauthenticated, network-accessible nature of the flaw and its critical CVSS score make it an attractive target if details become more widely known.
scw-seat-reservation plugin version ≤ 3.1 using tools like WPScan, Shodan, or Google dorks (e.g., inurl:wp-content/plugins/scw-seat-reservation).' OR 1=1-- or using time-based blind injection payloads (e.g., ' AND SLEEP(5)--) to confirm exploitability.sqlmap targeting the identified endpoint to enumerate databases, tables, and extract sensitive data (e.g., WordPress wp_users table for credentials, WooCommerce order data)./wp-admin/admin-ajax.php or plugin page slugs) with SQL metacharacters (', --, OR 1=1, UNION SELECT, SLEEP) in query parameters or POST bodies.UNION SELECT, information_schema, or wp_users; unauthorized changes to user account records or new admin accounts created.wp-content/plugins/scw-seat-reservation/ directory that were not part of the original plugin installation.The primary remediation is to update the Advance Seat Reservation Management for WooCommerce plugin to a version released after 3.1, which contains the fix (Feedly). If an update is not immediately available, site administrators should temporarily deactivate the plugin to eliminate the attack surface. Deploying a Web Application Firewall (WAF) — such as Wordfence or Cloudflare WAF — with rules targeting SQL injection patterns provides an additional layer of defense. A thorough security audit of the WordPress database for signs of unauthorized access is also recommended.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."