
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67945 is a SQL Injection vulnerability in the MailerLite – WooCommerce integration WordPress plugin (slug: woo-mailerlite) that allows unauthenticated remote attackers to execute arbitrary SQL commands against the underlying database. It affects all plugin versions up to and including 3.1.2, with version 3.1.3 containing the fix. The vulnerability was reported by researcher NumeX on November 4, 2025, and publicly disclosed by Patchstack on January 20–22, 2026. It carries a CVSS v3.1 base score of 9.3 (Critical), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and stems from insufficient sanitization or parameterization of user-supplied input before it is incorporated into SQL queries within the plugin. Because no authentication is required (PR:N) and no user interaction is needed (UI:N), an attacker can send a crafted HTTP request directly to a vulnerable endpoint exposed by the plugin on any WordPress/WooCommerce site running the affected version. The scope is marked as Changed (S:C), indicating that the impact extends beyond the plugin itself to the broader database and potentially the WordPress installation. No public proof-of-concept code has been identified, but Patchstack notes the vulnerability class is commonly used in mass-exploit campaigns (Patchstack).
Successful exploitation grants an unauthenticated attacker direct read access to the WordPress database, enabling theft of sensitive data including customer PII, order details, WooCommerce configuration, WordPress user credentials (hashed passwords), and API keys or secrets stored in the database. The Changed scope means the confidentiality impact is rated High and extends beyond the plugin's own data boundary. While availability impact is rated Low (limited disruption) and integrity impact is Low-to-None, credential theft could enable follow-on account takeover and full site compromise (Patchstack).
Patchstack has flagged this vulnerability as "Known to be exploited" and notes it is expected to be used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site traffic or popularity. The EPSS score is approximately 0.021% (0.000210), reflecting a relatively low but non-zero probability of exploitation in the near term. No specific threat actor attribution or public exploit kit inclusion has been reported. The vulnerability requires no authentication and no user interaction, making it trivially exploitable by automated scanners (Patchstack).
woo-mailerlite plugin installed and running version 3.1.2 or earlier.' OR 1=1-- or time-based blind injection payloads such as ' AND SLEEP(5)--).sqlmap targeting the identified endpoint to enumerate databases, tables, and extract sensitive records (e.g., wp_users, wp_options, order tables).', --, OR 1=1, UNION SELECT, SLEEP(, BENCHMARK() in query parameters or POST body.UNION, INFORMATION_SCHEMA, or SLEEP; unauthorized reads of wp_users or wp_options tables from the web application user.The vendor has released version 3.1.3 of the MailerLite – WooCommerce integration plugin, which resolves this vulnerability. Site administrators should update to version 3.1.3 or later immediately via the WordPress admin dashboard or WP-CLI. As a temporary workaround for sites unable to update immediately, Patchstack offers a virtual patching/mitigation rule that blocks exploitation attempts. Additionally, restricting database user privileges to the minimum required and enabling a web application firewall (WAF) with SQL injection rules can reduce risk (Patchstack).
Wordfence included CVE-2025-67945 in its weekly WordPress vulnerability report for the week of January 19–25, 2026, highlighting it as a notable SQL injection issue in the WooCommerce ecosystem (Wordfence). A social media post on Bluesky by a cybersecurity account also referenced the vulnerability in mid-2026, indicating continued community awareness. Patchstack, as the assigning CNA, emphasized the mass-exploit campaign risk associated with this vulnerability class in WordPress plugins.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."