VYPR
High severity7.6NVD Advisory· Published Sep 5, 2025· Updated Apr 23, 2026

CVE-2025-58788

CVE-2025-58788

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Blind SQL injection in License Manager for WooCommerce plugin (≤3.0.12) allows unauthenticated attackers to extract database contents.

Vulnerability

Overview

The License Manager for WooCommerce plugin for WordPress, versions 3.0.12 and earlier, contains a blind SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This flaw allows an attacker to inject maliciously craft input that is not properly sanitized before being used in database queries, enabling blind SQL injection attacks [1].

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending specially crafted requests to the plugin's endpoints. No authentication is required, making it accessible to any remote attacker. The blind nature means the attacker does not see direct error output but can infer information by observing differences in responses or timing [1].

Impact

Successful exploitation could allow a malicious actor to directly interact with the database, including but not limited to stealing sensitive information such as user credentials, license keys, and other stored data. This vulnerability is noted as being used in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

The vendor has released version 3.0.13 which resolves the vulnerability. Users are strongly advised to update immediately. If unable to update, users should contact their hosting provider or web developer for assistance. Patchstack users can enable auto-update for vulnerable plugins [1] plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.