SQL Injection Vulnerability in Quick Featured Images Plugin for WordPress
CVE-2025-11980
What is CVE-2025-11980?
The Quick Featured Images plugin for WordPress contains an SQL Injection vulnerability within the 'delete_orphaned' function, present in all versions up to and including 13.7.3. This security flaw arises from inadequate parameter escaping and insufficient preparation of the existing SQL query. Authenticated attackers, possessing Editor-level access or higher, can exploit this vulnerability to insert additional SQL commands into existing queries. This could enable them to extract sensitive database information, provided they manipulate an author-level user or above into adding a malicious custom field value.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Quick Featured Images * <= 13.7.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved