CVE-2025-28982: WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes wp-pipes allows SQL Injection.This issue affects WP Pipes: from n/a through <= 1.4.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28982?
CVE-2025-28982 has been classified as a high severity SQL Injection vulnerability.
How do I fix CVE-2025-28982?
To fix CVE-2025-28982, upgrade ThimPress WP Pipes to version 1.4.4 or later.
What types of attacks can CVE-2025-28982 facilitate?
CVE-2025-28982 can facilitate SQL injection attacks that may allow unauthorized access to the database.
Which versions of WP Pipes are affected by CVE-2025-28982?
CVE-2025-28982 affects all versions of WP Pipes from n/a up to and including 1.4.3.
Is CVE-2025-28982 specific to any particular platform?
Yes, CVE-2025-28982 specifically affects the ThimPress WP Pipes plugin for WordPress.