CVE-2025-30807
CVSS 3.1 Score 9.3 of 10 (high)
Details
Published Apr 1, 2025
Updated: Apr 2, 2025
CWE ID 89
Summary
CVE-2025-30807 is an SQL injection vulnerability affecting the Next-Cart Store to WooCommerce Migration plugin, with versions from n/a to 3.9.4 being impacted. Maliciously crafted input can manipulate SQL commands, allowing unauthorized access to sensitive data or even complete system takeover. The flaw arises due to insufficient validation and neutralization of user-supplied data. Users are strongly advised to update the plugin to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.