CVE-2025-31920: WordPress WP Guppy plugin <= 4.3.3 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech WP Guppy allows SQL Injection. This issue affects WP Guppy: from n/a through 4.3.3.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech WP Guppy wp-guppy allows SQL Injection.This issue affects WP Guppy: from n/a through <= 4.3.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31920?
CVE-2025-31920 has a severe impact due to its potential for SQL Injection attacks.
How do I fix CVE-2025-31920?
The recommended fix for CVE-2025-31920 is to update AmentoTech WP Guppy to version 4.3.4 or later.
What versions of AmentoTech WP Guppy are affected by CVE-2025-31920?
AmentoTech WP Guppy versions up to and including 4.3.3 are affected by CVE-2025-31920.
Can CVE-2025-31920 be exploited remotely?
Yes, CVE-2025-31920 could potentially be exploited remotely due to its SQL Injection nature.
Is there a workaround for CVE-2025-31920 if I cannot update the plugin?
There are currently no known workarounds for CVE-2025-31920, so it is essential to update to the patched version.