First published: Thu Jan 09 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ofek Nakar Virtual Bot allows Blind SQL Injection.This issue affects Virtual Bot: from n/a through 1.0.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ofek Nakar Virtual Bot | >=n/a<=1.0.0 | |
WordPress Virtual Bot Plugin | <=1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22542 is classified as a critical vulnerability due to its potential for allowing blind SQL injection.
To resolve CVE-2025-22542, upgrade the Ofek Nakar Virtual Bot to a version above 1.0.0.
CVE-2025-22542 describes an improper neutralization of special elements used in SQL commands, leading to an SQL injection vulnerability.
CVE-2025-22542 affects the Ofek Nakar Virtual Bot and the WordPress Virtual Bot Plugin up to version 1.0.0.
Yes, user data is at risk due to the potential exploitation of SQL injection vulnerabilities present in CVE-2025-22542.