SQL Injection Vulnerability in Gestion de tarifs Plugin for WordPress
CVE-2025-7662
6.5MEDIUM
What is CVE-2025-7662?
The Gestion de tarifs plugin for WordPress is vulnerable to SQL Injection stemming from the 'tarif' and 'intitule' shortcodes, due to inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject additional SQL queries into existing ones, potentially leading to unauthorized access and extraction of sensitive information from the database.
Affected Version(s)
Gestion de tarifs * <= 1.4