First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Office Locator allows SQL Injection. This issue affects Office Locator: from n/a through 1.3.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WebbyTemplate Office Locator | <=1.3.0 | |
WordPress Office Locator plugin | <=1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32665 is classified as a critical vulnerability due to its potential for SQL Injection exploitation.
To fix CVE-2025-32665, update the WebbyTemplate Office Locator or WordPress Office Locator plugin to the latest version beyond 1.3.0.
CVE-2025-32665 affects WebbyTemplate Office Locator and the WordPress Office Locator plugin up to version 1.3.0.
CVE-2025-32665 allows SQL Injection attacks, which can lead to unauthorized access to the database.
Organizations and individuals using WebbyTemplate Office Locator or the WordPress Office Locator plugin prior to version 1.3.0 are impacted by CVE-2025-32665.