CVE-2025-1446

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 23, 2025
Updated: Apr 2, 2025
CWE ID 89

Summary

CVE-2025-1446 is a vulnerability affecting the Pods WordPress plugin. Prior to version 3.2.8.2, the plugin fails to sanitize and escape a parameter used in a SQL statement, making it susceptible to SQL injection attacks. Unauthorized users with admin privileges can exploit this flaw to manipulate, retrieve, or modify sensitive data, potentially leading to serious security consequences. WordPress site administrators are advised to update the plugin to its latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share