mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information. | |
| Title | mooSocial Store Plugin 2.6 SQL Injection via product parameter | |
| First Time appeared |
Moosocial
Moosocial moosocial |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:moosocial:moosocial:2.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Moosocial
Moosocial moosocial |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-25T14:15:16.479Z
Reserved: 2026-05-25T13:46:29.723Z
Link: CVE-2018-25371
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T15:30:06Z
Weaknesses