CVE-2025-2186

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 22, 2025
CWE ID 908

Summary

CVE-2025-2186: The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress contains a critical SQL Injection vulnerability impacting all versions up to 3.5.1. This issue arises due to insufficient escaping of user-supplied data in the 'automationId' parameter and an absence of sufficient query preparation. Unauthenticated attackers can leverage this weakness to insert malicious SQL queries into existing ones, potentially extracting sensitive database information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share