PT-2025-30001 · WordPress · B1.Lt Plugin

Aurélien Bourdois

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-6718

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions B1.lt plugin for WordPress versions up to and including 2.2.56
Description The B1.lt plugin for WordPress is susceptible to SQL Injection due to a missing capability check on the b1 run query API endpoint. This allows authenticated attackers with Subscriber-level access or higher to execute arbitrary SQL commands.
Recommendations Update the B1.lt plugin to a version later than 2.2.56.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-6718

Affected Products

B1.Lt Plugin