External risk intelligence

WooCommerce Ultimate Gift Card Blind SQL Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-47569

The vulnerability exists in a WordPress plugin designed for WooCommerce, which is a web-based e-commerce platform. As a public-facing web component, such plugins are typically deployed on websites accessible from the internet to facilitate customer transactions and interactions.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in a widely used e-commerce plugin, potentially allowing unauthorized access to sensitive information. This vulnerability, categorized as SQL Injection, could enable attackers to extract data from systems utilizing this specific gift card functionality.

  • Flaw lets attackers steal business data.
  • Affects e-commerce and customer data.
  • Verify plugin relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted input through the plugin's web interface. This could allow them to inject malicious SQL commands, potentially leading to unauthorized access to sensitive data or disruption of service.

  • Attacker needs public web access.
  • Specially crafted input triggers the issue.
  • Risk of data exposure or service disruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the WooCommerce Ultimate Gift Card plugin could allow an attacker to inject malicious SQL commands into the system. This could potentially lead to the exposure of sensitive data stored within the WooCommerce environment, or impact the normal operation of the plugin's services.

  • Sensitive WooCommerce data
  • Via unauthenticated network requests
  • Data exposure or service disruption

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in the WooCommerce Ultimate Gift Card plugin requires immediate attention from teams managing e-commerce platforms and their associated plugins. The first step should be to identify all instances of this plugin across your environment, determine their reachability from external networks, assess their business criticality, and identify the accountable application or platform owner. Subsequent remediation planning should be risk-based and coordinated.

  • Identify plugin owner and scope.
  • Verify external reachability and impact.
  • Plan coordinated remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WooCommerce Ultimate Gift Card plugin?

It is a WordPress plugin that adds gift card functionality to online stores using WooCommerce. Merchants use it to manage, sell, and redeem digital gift cards within their e-commerce storefronts, integrating directly with the shopping cart and checkout experience.

What does SQL Injection mean for CVE-2025-47569?

This vulnerability, classified as CWE-89, happens when the plugin incorrectly handles user-provided input before using it in database queries. Because it is a 'Blind' SQL Injection, an attacker may be able to infer sensitive information from the database, even if the application does not display the results of the query directly on the screen.

How does an attacker trigger this vulnerability?

An attacker exploits this by sending specially crafted web requests to the plugin through an internet-facing interface. Normal site interactions, such as browsing products or checking out using standard plugin features, do not trigger this flaw; it specifically requires malicious inputs designed to manipulate the underlying database commands.

Is my website at risk from this CVE?

If you use the affected plugin versions on an internet-facing site, your risk is elevated because the plugin is designed for public e-commerce interactions. According to Halo Surface Signal, since this plugin operates as a public-facing web component to facilitate transactions, it is inherently reachable from the internet, increasing the potential for unauthorized data access.

What should I do if I run this software?

Your first step is to locate every instance of the WooCommerce Ultimate Gift Card plugin within your systems. Confirm which of these sites are accessible over the internet, determine who is responsible for managing each site, and prioritize those that handle sensitive customer information for further assessment.

References