PT-2025-5191 · WordPress · Typomedia Foundation Wordpress Custom Sidebar

João Pedro S Alcântara

·

Published

2025-01-16

·

Updated

2025-01-16

·

CVE-2025-23912

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Typomedia Foundation WordPress Custom Sidebar versions prior to 2.3
Description The issue is related to the improper neutralization of special elements used in an SQL command, allowing Blind SQL Injection. This problem enables attackers to execute malicious code.
Recommendations For versions prior to 2.3, update to a version that contains a fix for this issue to prevent Blind SQL Injection attacks. As a temporary workaround, consider restricting access to sensitive database areas until a patch is available.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-23912

Affected Products

Typomedia Foundation Wordpress Custom Sidebar