CVE-2025-22349
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Jan 7, 2025
CWE ID 89
Summary
CVE-2025-22349 is an SQL Injection vulnerability affecting the Owen Cutajar & Hyder Jaffari WordPress Auction Plugin. Hackers can exploit this issue, which exists from version n/a through 3.7, by inserting malicious SQL commands. The neutralization of special elements in these commands is handled improperly, allowing unauthorized SQL querying of the database and potentially exposing sensitive information or enabling further attacks. Users of this plugin are advised to update to a patched version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WordPress Auction Plugin
Affected Vendors
- WordPress