CVE-2025-30969: WordPress iFrame Images Gallery plugin <= 9.0 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Images Gallery allows SQL Injection. This issue affects iFrame Images Gallery: from n/a through 9.0.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Images Gallery wp-iframe-images-gallery allows SQL Injection.This issue affects iFrame Images Gallery: from n/a through <= 9.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30969?
CVE-2025-30969 is considered a high-severity SQL Injection vulnerability.
How do I fix CVE-2025-30969?
Fix CVE-2025-30969 by updating the GoPiPlus iFrame Images Gallery plugin to version 9.1 or later.
Which versions of iFrame Images Gallery are affected by CVE-2025-30969?
CVE-2025-30969 affects iFrame Images Gallery versions from n/a to 9.0.
What type of vulnerability is CVE-2025-30969?
CVE-2025-30969 is classified as an SQL Injection vulnerability.
Can CVE-2025-30969 be exploited remotely?
Yes, CVE-2025-30969 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.