First published: Sat Mar 15 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cookforweb All In Menu allows Blind SQL Injection. This issue affects All In Menu: from n/a through 1.1.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
cookforweb All In Menu | <=1.1.5 | |
WordPress All In Menu Plugin | <=1.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27281 is classified as a high-severity vulnerability due to its potential for exploitation through Blind SQL Injection.
To fix CVE-2025-27281, you should update the All In Menu plugin to version 1.1.6 or higher, which addresses this vulnerability.
CVE-2025-27281 affects the cookforweb All In Menu and the WordPress All In Menu Plugin versions up to 1.1.5.
CVE-2025-27281 is an SQL Injection vulnerability that allows an attacker to manipulate SQL queries.
Yes, exploitation of CVE-2025-27281 can potentially lead to unauthorized access to sensitive data within the database.