SQL Injection Vulnerability in WPRecovery Plugin for WordPress
CVE-2025-10726
9.1CRITICAL
What is CVE-2025-10726?
The WPRecovery plugin for WordPress is vulnerable to SQL Injection through the 'data[id]' parameter across all versions up to 2.0. This flaw is caused by inadequate escape mechanisms for user-supplied parameters and insufficient preparation of the SQL query. This vulnerability allows unauthenticated attackers to inject arbitrary SQL queries, potentially extracting sensitive database information. Moreover, the injection can lead to the manipulation of PHP functions, such as unlink(), putting the server at risk by enabling file deletions through crafted input.
Affected Version(s)
WPRecovery * <= 2.0