CVE-2025-31619
CVSS 3.1 Score 8.5 of 10 (high)
Details
Summary
CVE-2025-31619 is an SQL Injection vulnerability affecting marcoingraiti Actionwear products sync. The issue arises from improper neutralization of special elements in SQL commands, enabling attackers to inject malicious queries and potentially gain unauthorized access to sensitive data or modify database information. This vulnerability affects Actionwear products sync versions from n/a through 2.3.3. Successful exploitation could lead to serious consequences, including data theft or system compromise. It is recommended that users upgrade to the latest version of the product to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress