First published: Sun Mar 23 2025(Updated: )
The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pods WordPress plugin | <3.2.8.2 | |
Pods Foundation | <3.2.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1446 has a high severity rating due to its potential for SQL injection attacks.
To fix CVE-2025-1446, update the Pods WordPress plugin to version 3.2.8.2 or later.
Admins using the Pods WordPress plugin version prior to 3.2.8.2 are affected by CVE-2025-1446.
CVE-2025-1446 is a SQL injection vulnerability caused by the failure to sanitize user input.
The potential impacts of CVE-2025-1446 include unauthorized access to the database and possible data manipulation.