CVE-2025-27297
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Feb 24, 2025
CWE ID 89
Summary
CVE-2025-27297 is an SQL injection vulnerability affecting the Bravo Search & Replace software. The issue allows an attacker to execute blind SQL injection queries due to improper neutralization of special elements in SQL commands. This weakness exists in versions of the software from n/a through 1.0, making it crucial for users to apply the necessary patch or upgrade to mitigate the risk. An attacker could exploit this flaw to access, modify, or delete sensitive data, or even gain unauthorized system access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- WordPress