PT-2025-33712 · WordPress · Js Archive List

Michael Mazzolini

·

Published

2025-08-19

·

Updated

2025-08-24

·

CVE-2025-7670

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: JS Archive List plugin for WordPress versions up to and including 6.1.5
Description: The JS Archive List plugin for WordPress is susceptible to time-based SQL Injection through the build sql where() function. This is due to insufficient escaping of user-supplied parameters and inadequate preparation of existing SQL queries. This allows unauthenticated attackers to append additional SQL queries to existing queries, potentially enabling the extraction of sensitive information from the database.
Recommendations: Update the JS Archive List plugin to a version later than 6.1.5.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-7670

Affected Products

Js Archive List