CVE-2025-3951

The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:updraftplus:wp-optimize:*:*:*:*:*:wordpress:*:*

History

09 Jun 2025, 20:54

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ - () https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ - Exploit, Third Party Advisory
First Time Updraftplus wp-optimize
Updraftplus
CPE cpe:2.3:a:updraftplus:wp-optimize:*:*:*:*:*:wordpress:*:*
CWE CWE-89
Summary
  • (es) El complemento WP-Optimize para WordPress anterior a la versión 4.2.0 no escapa adecuadamente a la entrada del usuario al verificar los estados de compresión de imágenes, lo que podría permitir a los usuarios con rol de administrador realizar ataques de inyección SQL en el contexto de configuraciones de WordPress de varios sitios.

02 Jun 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.1
References () https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ - () https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ -

02 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-02 06:15

Updated : 2025-06-09 20:54


NVD link : CVE-2025-3951

Mitre link : CVE-2025-3951

CVE.ORG link : CVE-2025-3951


JSON object : View

Products Affected

updraftplus

  • wp-optimize
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')