CVE-2025-30819
CVSS 3.1 Score 8.5 of 10 (high)
Details
Summary
CVE-2025-30819 is a newly discovered SQL Injection vulnerability affecting the Simple Giveaways plugin, versions n/a through 2.48.1. An attacker can exploit this issue by injecting malicious SQL commands into the application, potentially gaining unauthorized access to sensitive data or even taking control of the system. The vulnerability stems from the plugin's failure to properly neutralize special elements used in SQL commands, making it an easy target for SQL Injection attacks. This flaw could put WordPress sites using the Simple Giveaways plugin at risk, requiring immediate attention and patch application to mitigate potential threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.