CVE-2025-2186
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Mar 22, 2025
CWE ID 908
Summary
CVE-2025-2186: The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress contains a critical SQL Injection vulnerability impacting all versions up to 3.5.1. This issue arises due to insufficient escaping of user-supplied data in the 'automationId' parameter and an absence of sufficient query preparation. Unauthenticated attackers can leverage this weakness to insert malicious SQL queries into existing ones, potentially extracting sensitive database information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.