Lucky Wheel for WooCommerce – Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags
high
The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13. This is due to the plugin using eval() to execute user-supplied input from the 'Conditional Tags' setting without proper validation or sanitization. This makes it possible...
- CVSS:
- 7.2
- Affected:
- up to 1.1.13
- Fixed in:
- 1.1.14
- Disclosed:
- Dec 29, 2025
CVE-2025-14509 on NVD →
Lucky Wheel for WooCommerce – Spin a Sale <= 1.0.10 - Cross-Site Scripting
medium
The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to Reflected and Stored Cross-Site Scripting via several parameters found in the /admin/admin.php file.
- CVSS:
- 6.4
- Affected:
- up to 1.0.10
- Fixed in:
- 1.0.11
- Disclosed:
- Apr 5, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database