Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

John Lee

#19162of 53,632
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-43587
6.5
2025-10-24
WordPress · Rapidresult · CVE-2025-10748
**Name of the Vulnerable Software and Affected Versions** RapidResult plugin for WordPress versions up to and including 1.2 **Description** The RapidResult plugin for WordPress is susceptible to SQL Injection due to insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries. Specifically, the `s` parameter is vulnerable. This allows authenticated attackers with contributor-level permissions or higher to inject additional SQL queries, potentially extracting sensitive information from the database. **Recommendations** Update the RapidResult plugin to a version newer than 1.2.
PT-2025-42305
7.5
2025-10-15
WordPress · Outdoor · CVE-2025-10743
**Name of the Vulnerable Software and Affected Versions** WordPress Outdoor plugin versions prior to 1.3.3 **Description** The Outdoor plugin for WordPress is susceptible to SQL Injection through the 'edit' action. This is due to inadequate escaping of user-supplied input and insufficient preparation of existing SQL queries. An unauthenticated attacker can inject additional SQL queries into existing database queries, potentially extracting sensitive information. The `edit` action and the user-supplied parameter are involved in this issue. **Recommendations** Update the Outdoor plugin to version 1.3.3 or later.