SQL Injection Vulnerability in WPRecovery Plugin for WordPress
CVE-2025-10726

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2025

What is CVE-2025-10726?

The WPRecovery plugin for WordPress is vulnerable to SQL Injection through the 'data[id]' parameter across all versions up to 2.0. This flaw is caused by inadequate escape mechanisms for user-supplied parameters and insufficient preparation of the SQL query. This vulnerability allows unauthenticated attackers to inject arbitrary SQL queries, potentially extracting sensitive database information. Moreover, the injection can lead to the manipulation of PHP functions, such as unlink(), putting the server at risk by enabling file deletions through crafted input.

Affected Version(s)

WPRecovery * <= 2.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.
CVE-2025-10726 : SQL Injection Vulnerability in WPRecovery Plugin for WordPress