The WP-Optimize  WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ | Exploit Third Party Advisory | 
Configurations
                    History
                    09 Jun 2025, 20:54
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Updraftplus wp-optimize Updraftplus | |
| CPE | cpe:2.3:a:updraftplus:wp-optimize:*:*:*:*:*:wordpress:*:* | |
| CWE | CWE-89 | |
| Summary | 
 | |
| References | () https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ - Exploit, Third Party Advisory | 
02 Jun 2025, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.1 | 
| References | () https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ - | 
02 Jun 2025, 06:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-02 06:15
Updated : 2025-06-09 20:54
NVD link : CVE-2025-3951
Mitre link : CVE-2025-3951
CVE.ORG link : CVE-2025-3951
JSON object : View
Products Affected
                updraftplus
- wp-optimize
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
