CVE-2025-14509

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13. This is due to the plugin using eval() to execute user-supplied input from the 'Conditional Tags' setting without proper validation or sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server. In WordPress multisite installations, this allows Site Administrators to execute arbitrary code, a capability they should not have since plugin/theme file editing is disabled for non-Super Admins in multisite environments.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    #ALERT CVE-2025-14509 (CVSS 7.2) - Lucky Wheel for WooCommerce plugin vulnerable to PHP Code Injection. Affects all versions ≤1.1.13. Authenticated attackers w/ admin access can execute arbitrary code. Update immediately. #CVE #Vulnerability #PatchNow #WordPress https://t.co/APiRTmqt0I

    0000019
    144 followersView on X

Explore more