CVE-2025-24587
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Jan 24, 2025
CWE ID 89
Summary
CVE-2025-24587 is a vulnerability affecting the Email Subscription Popup from I Thirteen Web Solutions, version n/a through 1.2.23. An SQL Injection flaw is present, which can be exploited to execute unauthorized SQL commands blindly. The vulnerability arises due to a lack of proper neutralization of special elements used in an SQL command. This issue could potentially lead to unauthorized access to sensitive data or system manipulation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Email Subscription Popup Plugin
Affected Vendors
- WordPress