Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-58788 PoC — WordPress License Manager for WooCommerce Plugin <= 3.0.12 - SQL Injection Vulnerability

Source
Associated Vulnerability
Title: WordPress License Manager for WooCommerce Plugin <= 3.0.12 - SQL Injection Vulnerability (CVE-2025-58788)
Description:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.
Description
WordPress License Manager for WooCommerce Plugin <= 3.0.12 is vulnerable to SQL Injection
Readme
SINK: The searchProducts() function does not validate input, leading to a SQL Injection vulnerability in the $term variable.
<img width="1037" height="709" alt="image" src="https://github.com/user-attachments/assets/e0a238e3-50e7-442d-8308-0d6799b5bb76" />

- The dropdownDataSearch() function with $type= 'product' allows to control the $term variable while calling the searchProducts() function.
<img width="1073" height="435" alt="image" src="https://github.com/user-attachments/assets/bc5fbc2d-8996-4b52-a46c-08b2c8e67755" />
<img width="920" height="623" alt="image" src="https://github.com/user-attachments/assets/8b487343-4745-4354-8847-dc2471e9ae89" />

POC:
<img width="1918" height="1026" alt="image" src="https://github.com/user-attachments/assets/4e965008-c3ae-4381-8909-7dace7b60e2e" />

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →