CVE-2025-32301: WordPress CountDown Pro WP Plugin <= 2.7 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown Pro WP Plugin allows SQL Injection. This issue affects CountDown Pro WP Plugin: from n/a through 2.7.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown Pro WP Plugin circularcountdown allows SQL Injection.This issue affects CountDown Pro WP Plugin: from n/a through <= 2.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32301?
CVE-2025-32301 is rated as a critical severity vulnerability due to the potential for SQL Injection.
How do I fix CVE-2025-32301?
To fix CVE-2025-32301, update the CountDown Pro WP Plugin to version 2.8 or later, which addresses the SQL Injection vulnerability.
What software is affected by CVE-2025-32301?
CVE-2025-32301 affects LambertGroup CountDown Pro WP Plugin versions up to and including 2.7.
What type of vulnerability is CVE-2025-32301?
CVE-2025-32301 is an SQL Injection vulnerability that allows attackers to manipulate SQL commands.
What are the risks associated with CVE-2025-32301?
Exploiting CVE-2025-32301 can potentially allow attackers to access or modify database contents, leading to data breaches.