SQL Injection Vulnerability in Paid Downloads Plugin by ichurakov
CVE-2025-68857
9.3CRITICAL
What is CVE-2025-68857?
An SQL Injection vulnerability exists in the ichurakov Paid Downloads plugin, allowing attackers to execute arbitrary SQL commands through user input. This issue can lead to unauthorized access to sensitive data in the database. Specifically, it affects versions from n/a up to 3.15. Users are advised to update their plugins to mitigate potential exploitation risks and ensure the security of their web applications.
Affected Version(s)
Paid Downloads 0 <= 3.15