CVE-2025-28939

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 89

Summary

CVE-2025-28939 is an SQL injection vulnerability affecting WP Google Calendar Manager. The flaw, which allows blind SQL injection, arises from the application's improper handling of special elements in SQL commands. Hackers can exploit this vulnerability to extract sensitive information from the affected system without any visible signs. This issue impacts WP Google Calendar Manager versions from n/a up to 2.1. Users are strongly advised to update to a patched version or take other appropriate security measures to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share