SQL Injection Vulnerability in Easy Email Subscription Plugin for WordPress
CVE-2025-10683
4.9MEDIUM
What is CVE-2025-10683?
The Easy Email Subscription plugin for WordPress is susceptible to SQL Injection via the 'uid' parameter, affecting all versions up to 1.3. This vulnerability arises from inadequate escaping of user-supplied input and insufficient preparation of the SQL query. Authenticated attackers with Administrator-level access can exploit this weakness to insert and execute additional SQL queries, potentially leading to unauthorized access to sensitive database information.
Affected Version(s)
Easy Email Subscription * <= 1.3