CVE-2018-25106
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Dec 23, 2024
CWE ID 89
CWE ID 74
Summary
CVE-2018-25106 is a critical vulnerability affecting the NebulaX Theme up to version 5.0 on WordPress. The issue lies within the nebula_send_to_hubspot function in the file Libs/Legacy/Legacy.php. An attacker can manipulate this function to carry out SQL injection, which may be executed remotely. To mitigate the risk, WordPress users should apply the patch with the commit ID 41230a81db0f671c570c2644bc2f80565ca83c5a.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.