CVE-2018-25106

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Dec 23, 2024
CWE ID 89
CWE ID 74

Summary

CVE-2018-25106 is a critical vulnerability affecting the NebulaX Theme up to version 5.0 on WordPress. The issue lies within the nebula_send_to_hubspot function in the file Libs/Legacy/Legacy.php. An attacker can manipulate this function to carry out SQL injection, which may be executed remotely. To mitigate the risk, WordPress users should apply the patch with the commit ID 41230a81db0f671c570c2644bc2f80565ca83c5a.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share