CVE-2025-30843
CVSS 3.1 Score 7.6 of 10 (high)
Details
Summary
CVE-2025-30843 is a significant SQL Injection vulnerability affecting the setriosoft bizcalendar-web application. The issue stems from improper neutralization of special elements used in SQL commands. An attacker can exploit this vulnerability to inject malicious SQL code and potentially gain unauthorized access to sensitive data or even take control of the affected system. The vulnerability exists in bizcalendar-web versions from n/a through 1.1.0.34. It is crucial for users to update their applications to a secure version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress