SQL Injection Vulnerability in Vibes Plugin for WordPress
CVE-2025-9172
7.5HIGH
What is CVE-2025-9172?
The Vibes plugin for WordPress has a vulnerability that allows for time-based SQL Injection via the āresourceā parameter. This issue is present in all versions up to and including 2.2.0, stemming from inadequate parameter escaping and a lack of sufficient preparation for the existing SQL query. Attackers can exploit this flaw to inject additional SQL commands, making it possible to extract sensitive information from the database without authentication.
Affected Version(s)
Vibes * <= 2.2.0