CVE-2025-13417: Plugin Organizer < 10.2.4 - Subscriber+ SQLi
Published Dec 29, 2025
·Updated
The Plugin Organizer WordPress plugin before 10.2.4 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers to perform SQL injection attacks.
Affected Software
1 affected component
WordPress Plugin Organizer<10.2.4
Event History
Dec 29, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
May 23, 57965
Event
via NVD·11:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-13417?
CVE-2025-13417 has a high severity as it allows SQL injection attacks that can compromise the database.
2
How do I fix CVE-2025-13417?
To fix CVE-2025-13417, update the Plugin Organizer plugin to version 10.2.4 or later.
3
Who is affected by CVE-2025-13417?
CVE-2025-13417 affects users of the Plugin Organizer WordPress plugin versions prior to 10.2.4.
4
What type of attack does CVE-2025-13417 allow?
CVE-2025-13417 allows subscribers to perform SQL injection attacks due to insufficient parameter sanitization.
5
What is the main issue with CVE-2025-13417?
The main issue with CVE-2025-13417 is the lack of sanitization and escaping of a parameter used in SQL statements.