Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting allows SQL Injection. This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through 3.1.
CVE ID: CVE-2025-31553
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Vendor: WPFactory
Product: Advanced WooCommerce Product Sales Reporting
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.2% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)