CVE-2025-3107: Newsletters <= 4.9.9.8 - Authenticated (Contributor+) SQL Injection orderby Parameter
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3107?
CVE-2025-3107 is classified as a critical vulnerability due to its potential for time-based SQL injection, exposing databases to unauthorized access.
How do I fix CVE-2025-3107?
To fix CVE-2025-3107, update the Newsletters plugin for WordPress to the latest version beyond 4.9.9.8 where the vulnerability has been patched.
What versions of the Newsletters plugin are affected by CVE-2025-3107?
CVE-2025-3107 affects all versions of the Newsletters plugin for WordPress up to and including version 4.9.9.8.
Can CVE-2025-3107 lead to data breaches?
Yes, CVE-2025-3107 can lead to data breaches as attackers could exploit the SQL injection vulnerability to access and manipulate sensitive database information.
Is there a workaround for CVE-2025-3107?
While updating the plugin is the recommended solution for CVE-2025-3107, a workaround may include temporarily disabling the plugin until the update is applied.