Code Injection in Sayan Datta's WP Last Modified Info Plugin
CVE-2025-52756

7.4HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-52756?

A vulnerability exists in the WP Last Modified Info plugin by Sayan Datta, allowing for code injection that results in remote code execution. This issue can be exploited by an attacker to execute arbitrary code on the server running the affected plugin, compromising the security of the WordPress site. The vulnerability impacts versions of the plugin from its initial release through version 1.9.2, posing a significant risk for users who have not updated. It's crucial for site administrators to address this vulnerability by implementing the recommended updates to ensure the integrity and security of their WordPress installation.

Affected Version(s)

WP Last Modified Info <= n/a

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zaim (Patchstack Alliance)
.