PT-2025-50892 · WordPress · Wpnakama

Athiwat Tiprasaharn

+6

·

Published

2025-12-12

·

Updated

2025-12-17

·

CVE-2025-14068

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WPNakama plugin for WordPress versions up to and including 0.6.3
Description The WPNakama plugin for WordPress is susceptible to time-based SQL Injection through the order by parameter. Insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries allow unauthenticated attackers to inject additional SQL queries, potentially extracting sensitive information from the database. The vulnerable parameter is order by.
Recommendations Update the WPNakama plugin to a version newer than 0.6.3.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-14068

Affected Products

Wpnakama