CVE-2025-30788

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Mar 27, 2025
CWE ID 352

Summary

CVE-2025-30788 is a significant cybersecurity vulnerability affecting the Eli EZ SQL Reports Shortcode Widget and DB Backup. This issue is a Cross-Site Request Forgery (CSRF) vulnerability, which enables an attacker to manipulate user actions on a web application without their knowledge or consent. Additionally, SQL Injection is possible through this vulnerability, granting unauthorized access to data. These issues impact versions of the EZ SQL Reports Shortcode Widget and DB Backup from n/a through 5.25.08. Successful exploitation could result in unintended data modifications or leakage, emphasizing the need for immediate mitigation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share