PT-2025-15412 · WordPress · Coreactivity

Yasng

+1

·

Published

2025-04-08

·

Updated

2025-04-09

·

CVE-2025-3436

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: coreActivity: Activity Logging plugin for WordPress versions prior to 2.8
Description: The issue arises from insufficient escaping of user-supplied parameters order and orderby, and a lack of proper preparation of existing SQL queries. This allows authenticated attackers with Subscriber-level access or higher to append additional SQL queries to existing ones, potentially extracting sensitive information from the database.
Recommendations: For versions prior to 2.8, update to a version that includes a fix for this issue, as the current version is vulnerable to SQL injection attacks via the order and orderby parameters. As a temporary workaround, consider restricting access to the order and orderby parameters in the affected plugin until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-3436

Affected Products

Coreactivity