CVE-2025-28939
CVSS 3.1 Score 8.5 of 10 (high)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 89
Summary
CVE-2025-28939 is an SQL injection vulnerability affecting WP Google Calendar Manager. The flaw, which allows blind SQL injection, arises from the application's improper handling of special elements in SQL commands. Hackers can exploit this vulnerability to extract sensitive information from the affected system without any visible signs. This issue impacts WP Google Calendar Manager versions from n/a up to 2.1. Users are strongly advised to update to a patched version or take other appropriate security measures to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.