---
id: CVE-2025-14509
title: >-
  The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is
  vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13
summary: >-
  The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is
  vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13.
  This is due to the plugin using eval() to execute user-supplied input from the
  'Conditio…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2025-12-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T08:10:00.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14509'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/woo-lucky-wheel/tags/1.1.13/frontend/frontend.php#L127
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/woo-lucky-wheel/trunk/frontend/frontend.php#L127
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3428063/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/9a41bc0e-0ab9-4cee-b3ca-d730c828782c?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00643
epssPercentile: 0.48782
ingestedAt: '2026-10-01T08:40:11.718Z'
---

## Overview

The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13. This is due to the plugin using eval() to execute user-supplied input from the 'Conditional Tags' setting without proper validation or sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server. In WordPress multisite installations, this allows Site Administrators to execute arbitrary code, a capability they should not have since plugin/theme file editing is disabled for non-Super Admins in multisite environments.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
