SQL Injection Flaw in Likes and Dislikes Plugin for WordPress
CVE-2025-5287
7.5HIGH
What is CVE-2025-5287?
The Likes and Dislikes Plugin for WordPress contains a vulnerability that allows SQL Injection through the 'post' parameter. This occurs due to inadequate escaping of user-supplied input and improper preparation of the SQL query. As a result, unauthenticated attackers can manipulate existing SQL queries to inject arbitrary queries, potentially exposing sensitive data from the database. It is crucial for users of this plugin to apply security measures and check for updates to safeguard their sites.
Affected Version(s)
Likes and Dislikes Plugin * <= 1.0.0