The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ | Exploit Third Party Advisory |
Configurations
History
09 Jun 2025, 20:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ - Exploit, Third Party Advisory | |
First Time |
Updraftplus wp-optimize
Updraftplus |
|
CPE | cpe:2.3:a:updraftplus:wp-optimize:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-89 | |
Summary |
|
02 Jun 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.1 |
References | () https://wpscan.com/vulnerability/220c195f-3df3-4883-8e0b-a0cf019e6323/ - |
02 Jun 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-02 06:15
Updated : 2025-06-09 20:54
NVD link : CVE-2025-3951
Mitre link : CVE-2025-3951
CVE.ORG link : CVE-2025-3951
JSON object : View
Products Affected
updraftplus
- wp-optimize
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')