SQL Injection Vulnerability in WP Employee Attendance System by Suhas Surse
CVE-2025-28972
7.6HIGH
What is CVE-2025-28972?
The WP Employee Attendance System by Suhas Surse is susceptible to a SQL Injection vulnerability which allows attackers to execute arbitrary SQL commands via user input. This enables potential data exposure and manipulation threats. The issue affects versions of the plugin up to 3.5, highlighting the need for urgent updates and security measures to protect sensitive information.
Affected Version(s)
WP Employee Attendance System <= 3.5