SQL Injection Vulnerability in WP jQuery Pager Plugin for WordPress
CVE-2025-10575
6.5MEDIUM
What is CVE-2025-10575?
The WP jQuery Pager plugin for WordPress is susceptible to SQL Injection due to inadequate escaping of the 'ids' shortcode attribute parameter, as processed by the WPJqueryPaged::get_gallery_page_imgs() function. This flaw affects all versions up to and including 1.4.0, allowing authenticated attackers with Contributor-level or higher access to append malicious SQL queries to existing ones. Consequently, attackers could potentially extract sensitive data from the database, posing a significant risk to the integrity and confidentiality of user information.
Affected Version(s)
WP jQuery Pager * <= 1.4.0