SQL Injection Vulnerability in GSpeech TTS Plugin for WordPress
CVE-2025-10187
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 October 2025
What is CVE-2025-10187?
The GSpeech TTS – WordPress Text To Speech Plugin contains a vulnerability stemming from insufficient input validation on the 'field' parameter. This weakness enables authenticated attackers with Administrator-level privileges to manipulate existing SQL queries by appending additional commands, potentially allowing unauthorized access to sensitive data stored in the database. It's crucial for users of the affected versions to implement the latest security updates to mitigate this risk.
Affected Version(s)
GSpeech TTS – WordPress Text To Speech Plugin * <= 3.17.3