CVE-2025-2317

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 89

Summary

CVE-2025-2317 is a vulnerability affecting the Product Filter by WBW plugin for WordPress. Maliciously crafted inputs to the filtersDataBackend parameter can lead to time-based SQL injection, allowing unauthenticated attackers to append additional SQL queries to existing ones. Consequently, sensitive information from the database can be extracted. This issue stems from insufficient escaping of user-supplied data and a lack of adequate preparation of existing SQL queries. Versions up to and including 2.7.9 of the plugin are vulnerable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share