CVE-2018-25371: Moosocial Store Plugin

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.

Affected products

  • Moosocial Moosocial Store Plugin: version 2.6 only

Published 2026-05-25. Last modified 2026-07-23.