CVE-2025-14124: Team < 5.0.11 - Unauthenticated SQLi
Published Jan 5, 2026
·Updated
The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Affected Software
1 affected component
wordpress/team<5.0.11
Event History
Jan 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-14124?
CVE-2025-14124 is classified as a critical severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2025-14124?
To fix CVE-2025-14124, update the Team WordPress plugin to version 5.0.11 or later.
3
Who is affected by CVE-2025-14124?
The vulnerability affects all versions of the Team WordPress plugin before 5.0.11.
4
What type of vulnerability is CVE-2025-14124?
CVE-2025-14124 is a SQL injection vulnerability that allows attackers to execute arbitrary SQL code.
5
Can CVE-2025-14124 be exploited by unauthenticated users?
Yes, CVE-2025-14124 can be exploited by unauthenticated users via AJAX actions.