CVE-2025-1986: Gutentor < 3.4.7 - Admin+ SQL Injection
The Gutentor WordPress plugin before 3.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1986?
CVE-2025-1986 is classified as a medium severity vulnerability due to its potential to allow SQL injection attacks.
How do I fix CVE-2025-1986?
To fix CVE-2025-1986, update the Gutentor plugin to version 3.4.7 or later, which includes the necessary security patches.
Who is affected by CVE-2025-1986?
CVE-2025-1986 affects users of the Gutentor WordPress plugin versions prior to 3.4.7.
What type of vulnerability is CVE-2025-1986?
CVE-2025-1986 is an SQL injection vulnerability that occurs due to improper sanitization and escaping of SQL query parameters.
What can attackers do with CVE-2025-1986?
Attackers exploiting CVE-2025-1986 may execute arbitrary SQL queries on the database, potentially leading to data leakage or corruption.