CVE-2025-4840
HIGH 7.5EPSS 0.5%
The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 0.52% chance of exploitation in the next 30 days, 42th percentile
- Published
- 2025-06-10
Proof-of-concept exploits (2)
- https://wpscan.com/vulnerability/85dc579d-edc4-421e-9bb1-09629dec527b/
- RandomRobbieBF/CVE-2025-48400★ · 2025-07-10