First published: Mon Mar 24 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marcel-NL Super Simple Subscriptions allows SQL Injection. This issue affects Super Simple Subscriptions: from n/a through 1.1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Super Simple Subscriptions | >=1.1.0 | |
WordPress Super Simple Subscriptions | <=1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30523 is classified as a critical vulnerability due to its potential for SQL Injection, allowing attackers to manipulate database queries.
To fix CVE-2025-30523, update the Super Simple Subscriptions plugin to version 1.1.1 or higher, where this vulnerability has been addressed.
CVE-2025-30523 affects Super Simple Subscriptions from n/a to version 1.1.0.
Exploiting CVE-2025-30523 can lead to unauthorized access to sensitive data and potential data manipulation within the affected database.
Yes, CVE-2025-30523 specifically affects the Super Simple Subscriptions plugin for WordPress.