CVE-2025-2319
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-2319 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress. Versions 4.11.13 to 5.25.08 are susceptible to this issue due to improper or missing nonce validation in the 'ELISQLREPORTS_menu' function. Exploitation requires an attacker to trick a site administrator into executing a malicious request, potentially leading to code execution on the server. This vulnerability has been addressed in version 5.25.10, which now includes a nonce check. However, it's important to note that this update makes the vulnerability exploitable only by administrators.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress