• XSS.stack #1 – первый литературный журнал от юзеров форума

!--One of the controversial WP vulnerabilities in 2025--!

NextGenPentesters

HDD-drive
Пользователь
Регистрация
07.05.2024
Сообщения
26
Реакции
6
CVE-2025-22783 is a critical SQL Injection vulnerability in the "SEO Plugin by Squirrly SEO" for WordPress, affecting versions 12.4.01 and earlier. Users with Contributor-level access or higher can input malicious search terms that are directly incorporated into database queries without proper validation, allowing attackers to execute arbitrary SQL commands. This flaw originates from inadequate sanitation of user input in the plugin's internal links management feature. To mitigate this issue, users should update to the latest plugin version and implement stringent input validation measures. For detailed technical insights and a proof of concept, refer to the GitHub repository dedicated to this vulnerability.

 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх