PT-2025-12780 · WordPress · Ez Sql Reports Shortcode Widget+1

Lucky_Buddy

·

Publicado

2025-03-25

·

Atualizado

2025-03-30

·

CVE-2025-2319

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress versions 4.11.13 through 5.25.08
Description The issue is related to Cross-Site Request Forgery due to missing or incorrect nonce validation on the ELISQLREPORTS menu function. This allows unauthenticated attackers to execute code on the server via a forged request if they can trick a site administrator into performing an action. However, in version 5.25.10, a nonce check is added, which limits the exploitability to admins only.
Recommendations For versions 4.11.13 through 5.25.08, upgrade to version 5.25.10 to add a nonce check and limit the vulnerability's exploitability. As a temporary workaround, consider restricting access to the ELISQLREPORTS menu function until the upgrade to version 5.25.10 is applied.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-2319

Produtos afetados

Db Backup
Ez Sql Reports Shortcode Widget