CVE-2025-24612

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping for Nova Poshta nova-poshta-ttn allows SQL Injection.This issue affects Shipping for Nova Poshta: from n/a through <= 1.19.6.
Configurations

No configuration.

History

23 Apr 2026, 15:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.3

01 Apr 2026, 17:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.3
v2 : unknown
v3 : unknown
Summary
  • (es) Vulnerabilidad de neutralización inadecuada de elementos especiales utilizados en un comando SQL ("inyección SQL") en MORKVA Shipping for Nova Poshta permite la inyección SQL. Este problema afecta a Shipping for Nova Poshta: desde n/a hasta 1.19.6.
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MORKVA Shipping for Nova Poshta allows SQL Injection. This issue affects Shipping for Nova Poshta: from n/a through 1.19.6. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping for Nova Poshta nova-poshta-ttn allows SQL Injection.This issue affects Shipping for Nova Poshta: from n/a through <= 1.19.6.
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/nova-poshta-ttn/vulnerability/wordpress-shipping-for-nova-poshta-plugin-1-19-6-sql-injection-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/nova-poshta-ttn/vulnerability/wordpress-shipping-for-nova-poshta-plugin-1-19-6-sql-injection-vulnerability?_s_id=cve -

27 Jan 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 14:15

Updated : 2026-06-17 08:59


NVD link : CVE-2025-24612

Mitre link : CVE-2025-24612

CVE.ORG link : CVE-2025-24612


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')