PT-2025-40474 · WordPress · Wp Dispatcher

Youcef Hamdani

·

Published

2025-10-03

·

Updated

2025-10-08

·

CVE-2025-10582

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Dispatcher plugin for WordPress versions up to and including 1.2.0
Description The WP Dispatcher plugin for WordPress is susceptible to SQL Injection via the id parameter. Insufficient escaping of user-supplied input and a lack of proper SQL query preparation allow authenticated attackers with Contributor-level access or higher to append additional SQL queries to existing ones. This can lead to the extraction of sensitive information from the database.
Recommendations Update the WP Dispatcher plugin to a version newer than 1.2.0.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10582

Affected Products

Wp Dispatcher