SQL Injection Vulnerability in AHAthat Plugin for WordPress
CVE-2025-2511
4.9MEDIUM
What is CVE-2025-2511?
The AHAthat Plugin for WordPress contains a time-based SQL Injection vulnerability in all versions up to and including 1.6. This vulnerability arises from insufficient escaping of user-supplied data in the 'id' parameter and a lack of proper preparation of the existing SQL query. As a result, authenticated attackers with Administrator-level access can manipulate the SQL queries, allowing them to execute malicious commands and extract sensitive information directly from the database.
Affected Version(s)
AHAthat Plugin * <= 1.6