Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlist-for-woocommerce allows SQL Injection.This issue affects NC Wishlist for Woocommerce: from n/a through <= 1.0.1.
Security readout for executives and security teams
Plain-English summary
CVE-2025-22505 is a high-severity SQL injection flaw in the WordPress NC Wishlist for Woocommerce plugin from Crispweb, affecting versions through 1.0.1. A logged-in attacker could potentially read sensitive database data and cause limited availability impact. No active exploitation is reported in the provided sources or CISA KEV data.
Executive priority
Treat this as a near-term remediation item for any WooCommerce site using the plugin, especially sites with customer logins. Prioritize inventory first because exposure depends on plugin presence and version. Escalate if the plugin is internet-facing and public registration is enabled.
Technical view
The issue is CWE-89 SQL injection in nc-wishlist-for-woocommerce. The CVSS 3.1 score is 8.5, with network access, low attack complexity, low privileges required, no user interaction, changed scope, high confidentiality impact, no integrity impact, and low availability impact. The provided sources do not include exploit details or a confirmed fixed version.
Likely exposure
Exposure is likely limited to WordPress sites running Crispweb NC Wishlist for Woocommerce version 1.0.1 or earlier. Because privileges are required, risk is higher on sites allowing customer accounts, subscribers, or other low-privilege logins.
Exploitation context
The CVSS vector indicates remote exploitation by an authenticated low-privilege user without user interaction. The likely business concern is database confidentiality, including potential access to WordPress or WooCommerce-related data. Active exploitation is not confirmed by the supplied sources.
Researcher notes
The record is source-limited. Patchstack and CVE describe SQL injection through version 1.0.1, but the supplied data does not name a vulnerable parameter, proof of concept, exploit status, or fixed release. Do not assume exploitation in the wild without additional evidence.
Mitigation direction
Inventory WordPress sites for nc-wishlist-for-woocommerce version 1.0.1 or earlier.
Check the vendor, WordPress plugin page, or Patchstack for an official fixed version.
Update the plugin if a vendor-approved patched release is available.
Disable or remove the plugin if it is unnecessary or no fix is available.
Restrict creation and use of low-privilege accounts where business operations allow.
Monitor database and application logs for unusual errors or suspicious authenticated activity.
Validation and detection
Confirm whether the plugin slug nc-wishlist-for-woocommerce is installed.
Record the installed plugin version on every WordPress instance.
Identify sites that allow public registration or broad low-privilege access.
Verify remediation by confirming removal, disabling, or installation of a vendor-approved fixed version.
Review security monitoring for suspicious authenticated requests involving the plugin.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-89: Database access and collection lookup
Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.