SQL Injection Vulnerability in Ads Pro Plugin for WordPress by CodeCanyon
CVE-2025-4381

7.5HIGH

What is CVE-2025-4381?

The Ads Pro Plugin for WordPress is susceptible to an SQL Injection attack through the ‘$id’ parameter in the getSpace() function. This vulnerability arises from inadequate escaping of user-supplied input and insufficient preparation of the SQL query. Malicious actors can exploit this flaw to insert additional SQL commands and potentially access sensitive data from the database, posing a significant risk to WordPress sites using affected versions of the plugin.

Affected Version(s)

Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager * <= 4.89

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TrÆ°ÆĄng Hữu PhĂșc (truonghuuphuc)
.