SQL Injection Vulnerability in NotFound Local SEO Plugin for WordPress
CVE-2025-23931

9.3CRITICAL

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
22 January 2025

Summary

A vulnerability exists in the NotFound WordPress Local SEO plugin allowing for Blind SQL Injection. This flaw can enable attackers to manipulate SQL queries executed by the application. If exploited, it can lead to unauthorized data access and potential compromise of sensitive information. Users are urged to update to the latest version and implement security measures to safeguard their websites.

Affected Version(s)

WordPress Local SEO <= 2.3

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aiden (Thái An) (Patchstack Alliance)
.