
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69337 is a Blind SQL Injection vulnerability in the Wolmart Core WordPress plugin developed by don-themes (d-themes). It affects all versions of Wolmart Core through 1.9.6 and allows unauthenticated remote attackers to extract sensitive database contents without direct visibility of query results. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 9.3 (Critical) (Feedly, Wordfence).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from insufficient sanitization of user-supplied input before it is incorporated into SQL queries within the Wolmart Core plugin. Because the injection is "blind," query results are not directly returned to the attacker; instead, the attacker infers database contents through boolean-based or time-based side-channel techniques. No authentication or user interaction is required, and the attack is conducted entirely over the network, making it trivially accessible to remote, unauthenticated adversaries (Feedly).
Successful exploitation allows an unauthenticated attacker to extract the full contents of the WordPress database, potentially exposing user credentials, personal data, order information, and other confidential records stored by the Wolmart WooCommerce theme. The CVSS scoring reflects a high confidentiality impact with a changed scope, indicating that data beyond the plugin's immediate context may be accessible. Availability is also marginally degraded due to the resource overhead of blind injection queries, though integrity is not directly impacted (Feedly).
There is currently no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.021%, reflecting a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Despite the absence of active exploitation, the unauthenticated, network-accessible attack vector and critical CVSS score make it a high-priority patching target.
/wp-content/plugins/wolmart-core/) or using tools like WPScan.AND SLEEP(5) or conditional expressions) to confirm the injection point without direct output.sqlmap with blind injection techniques to enumerate databases, tables, and columns, then dump sensitive data such as WordPress user hashes and WooCommerce order records.', --, AND, SLEEP, BENCHMARK) in query parameters.Site administrators should immediately update the Wolmart Core plugin to a version newer than 1.9.6, which is the primary and recommended remediation (Feedly, Wordfence). As interim mitigations, deploying a Web Application Firewall (WAF) with SQL injection detection rules can help block exploitation attempts. Additionally, restricting database user privileges to the minimum required and enabling slow query logging can limit impact and improve detection.
Wordfence included CVE-2025-69337 in its weekly WordPress vulnerability report for the period of February 16–22, 2026, highlighting it as a notable SQL injection issue in the Wolmart Core plugin (Wordfence). No significant additional vendor statements or notable researcher commentary beyond standard vulnerability database entries have been observed at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."