SQL Injection Vulnerability in TARIFFUXX Plugin for WordPress
CVE-2025-10682
6.5MEDIUM
What is CVE-2025-10682?
The TARIFFUXX plugin for WordPress is susceptible to SQL Injection due to inadequate handling of user-generated input incorporated directly into SQL queries. This vulnerability empowers authenticated users, who possess Contributor-level access or higher, to manipulate SQL statements effectively. By crafting specific attributes in the 'tariffuxx_configurator' shortcode, attackers can gain unauthorized access to extract sensitive database information.
Affected Version(s)
TARIFFUXX * <= 1.4