CVE-2025-22349

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 89

Summary

CVE-2025-22349 is an SQL Injection vulnerability affecting the Owen Cutajar & Hyder Jaffari WordPress Auction Plugin. Hackers can exploit this issue, which exists from version n/a through 3.7, by inserting malicious SQL commands. The neutralization of special elements in these commands is handled improperly, allowing unauthorized SQL querying of the database and potentially exposing sensitive information or enabling further attacks. Users of this plugin are advised to update to a patched version as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • WordPress Auction Plugin

Affected Vendors

  • WordPress