SQL Injection Vulnerability in NotFound Local SEO Plugin for WordPress
CVE-2025-23931
9.3CRITICAL
Summary
A vulnerability exists in the NotFound WordPress Local SEO plugin allowing for Blind SQL Injection. This flaw can enable attackers to manipulate SQL queries executed by the application. If exploited, it can lead to unauthorized data access and potential compromise of sensitive information. Users are urged to update to the latest version and implement security measures to safeguard their websites.
Affected Version(s)
WordPress Local SEO <= 2.3
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aiden (Thái An) (Patchstack Alliance)