CVE-2025-30947: WordPress Cool fade popup plugin <= 10.1 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade popup allows Blind SQL Injection. This issue affects Cool fade popup: from n/a through 10.1.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade popup cool-fade-popup allows Blind SQL Injection.This issue affects Cool fade popup: from n/a through <= 10.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30947?
CVE-2025-30947 is classified as a high-severity SQL injection vulnerability.
How do I fix CVE-2025-30947?
To fix CVE-2025-30947, update the Gopiplus Cool fade popup to version 10.2 or later.
What type of attack does CVE-2025-30947 enable?
CVE-2025-30947 allows for blind SQL injection attacks.
Which versions are affected by CVE-2025-30947?
CVE-2025-30947 affects Gopiplus Cool fade popup versions from n/a to 10.1.
Does CVE-2025-30947 affect WordPress installations?
Yes, CVE-2025-30947 also affects the WordPress implementation of the Cool fade popup plugin up to version 10.1.