SQL Injection Vulnerability in miniOrange Custom API for WordPress
CVE-2025-54048
9.3CRITICAL
What is CVE-2025-54048?
The miniOrange Custom API for WordPress contains an SQL injection vulnerability that allows an attacker to manipulate database queries. This flaw can lead to unauthorized access to sensitive data or the execution of arbitrary SQL commands. The affected versions range from n/a to 4.2.2, making it crucial for users to update or apply security measures to mitigate potential risks.
Affected Version(s)
Custom API for WP <= 4.2.2