CVE-2025-58788
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Blind SQL injection in License Manager for WooCommerce plugin (≤3.0.12) allows unauthenticated attackers to extract database contents.
Vulnerability
Overview
The License Manager for WooCommerce plugin for WordPress, versions 3.0.12 and earlier, contains a blind SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This flaw allows an attacker to inject maliciously craft input that is not properly sanitized before being used in database queries, enabling blind SQL injection attacks [1].
Exploitation
An unauthenticated attacker can exploit this vulnerability by sending specially crafted requests to the plugin's endpoints. No authentication is required, making it accessible to any remote attacker. The blind nature means the attacker does not see direct error output but can infer information by observing differences in responses or timing [1].
Impact
Successful exploitation could allow a malicious actor to directly interact with the database, including but not limited to stealing sensitive information such as user credentials, license keys, and other stored data. This vulnerability is noted as being used in mass-exploit campaigns targeting thousands of websites [1].
Mitigation
The vendor has released version 3.0.13 which resolves the vulnerability. Users are strongly advised to update immediately. If unable to update, users should contact their hosting provider or web developer for assistance. Patchstack users can enable auto-update for vulnerable plugins [1] plugins [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=3.0.12+ 1 more
- (no CPE)range: <=3.0.12
- (no CPE)range: <=3.0.12
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.