Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2.
CVE ID: CVE-2025-47643
CVSS Base Severity: HIGH
CVSS Base Score: 7.6
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Vendor: ELEXtensions
Product: ELEX Product Feed for WooCommerce
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 9.16% (scored less or equal to compared to others)
EPSS Date: 2025-05-13 (when was this score calculated)