SQL Injection Vulnerability in miniOrange Custom API for WordPress
CVE-2025-54048

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-54048?

The miniOrange Custom API for WordPress contains an SQL injection vulnerability that allows an attacker to manipulate database queries. This flaw can lead to unauthorized access to sensitive data or the execution of arbitrary SQL commands. The affected versions range from n/a to 4.2.2, making it crucial for users to update or apply security measures to mitigate potential risks.

Affected Version(s)

Custom API for WP <= 4.2.2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hiro (Code016Hiro) (Patchstack Alliance)
.