SQL Injection Vulnerability in Link to URL / Post Plugin by Sudipto
CVE-2025-25116

7.6HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
7 February 2025

Summary

The Link to URL / Post Plugin developed by Sudipto is susceptible to a SQL Injection vulnerability that allows attackers to execute arbitrary SQL commands through the post submission process. This flaw can be exploited via specially crafted input, leading to unauthorized access to database information. Attackers could leverage Blind SQL Injection techniques to infer data from the database without direct visibility, causing potential data breaches and compromise of application integrity. Users are encouraged to upgrade to the latest version to mitigate the risk.

Affected Version(s)

Link to URL / Post <= 1.3

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tri Doan (Patchstack Alliance)
.