CVE-2025-2319

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 352

Summary

CVE-2025-2319 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress. Versions 4.11.13 to 5.25.08 are susceptible to this issue due to improper or missing nonce validation in the 'ELISQLREPORTS_menu' function. Exploitation requires an attacker to trick a site administrator into executing a malicious request, potentially leading to code execution on the server. This vulnerability has been addressed in version 5.25.10, which now includes a nonce check. However, it's important to note that this update makes the vulnerability exploitable only by administrators.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share