PT-2026-45625 · Undefined · Undefined

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2018-25434

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wpas keys parameter. Attackers can send GET requests to autosuggest.php with crafted wpas keys values to extract sensitive database information from WordPress posts and other tables.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2018-25434

Affected Products

Undefined