LiveActive security incident?Get immediate response
CVE Record

CVE-2025-22505: WordPress NC Wishlist for Woocommerce Plugin <= 1.0.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlist-for-woocommerce allows SQL Injection.This issue affects NC Wishlist for Woocommerce: from n/a through <= 1.0.1.

HighCVSS 8.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2025-22505 is a high-severity SQL injection flaw in the WordPress NC Wishlist for Woocommerce plugin from Crispweb, affecting versions through 1.0.1. A logged-in attacker could potentially read sensitive database data and cause limited availability impact. No active exploitation is reported in the provided sources or CISA KEV data.

Executive priority

Treat this as a near-term remediation item for any WooCommerce site using the plugin, especially sites with customer logins. Prioritize inventory first because exposure depends on plugin presence and version. Escalate if the plugin is internet-facing and public registration is enabled.

Technical view

The issue is CWE-89 SQL injection in nc-wishlist-for-woocommerce. The CVSS 3.1 score is 8.5, with network access, low attack complexity, low privileges required, no user interaction, changed scope, high confidentiality impact, no integrity impact, and low availability impact. The provided sources do not include exploit details or a confirmed fixed version.

Likely exposure

Exposure is likely limited to WordPress sites running Crispweb NC Wishlist for Woocommerce version 1.0.1 or earlier. Because privileges are required, risk is higher on sites allowing customer accounts, subscribers, or other low-privilege logins.

Exploitation context

The CVSS vector indicates remote exploitation by an authenticated low-privilege user without user interaction. The likely business concern is database confidentiality, including potential access to WordPress or WooCommerce-related data. Active exploitation is not confirmed by the supplied sources.

Researcher notes

The record is source-limited. Patchstack and CVE describe SQL injection through version 1.0.1, but the supplied data does not name a vulnerable parameter, proof of concept, exploit status, or fixed release. Do not assume exploitation in the wild without additional evidence.

Mitigation direction

  • Inventory WordPress sites for nc-wishlist-for-woocommerce version 1.0.1 or earlier.
  • Check the vendor, WordPress plugin page, or Patchstack for an official fixed version.
  • Update the plugin if a vendor-approved patched release is available.
  • Disable or remove the plugin if it is unnecessary or no fix is available.
  • Restrict creation and use of low-privilege accounts where business operations allow.
  • Monitor database and application logs for unusual errors or suspicious authenticated activity.

Validation and detection

  • Confirm whether the plugin slug nc-wishlist-for-woocommerce is installed.
  • Record the installed plugin version on every WordPress instance.
  • Identify sites that allow public registration or broad low-privilege access.
  • Verify remediation by confirming removal, disabling, or installation of a vendor-approved fixed version.
  • Review security monitoring for suspicious authenticated requests involving the plugin.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-89: Database access and collection lookup

Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-22505 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L3.14.7Patchstack

Vulnerability scoring details

Base CVSS 3.1 score

8.5High
CVSS 3.1 vector shape for CVE-2025-22505Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CrispwebNC Wishlist for Woocommercenc-wishlist-for-woocommerce, 0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.