First published: Thu Apr 24 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar Frontend Dashboard allows SQL Injection. This issue affects Frontend Dashboard: from n/a through 2.2.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Frontend Dashboard | <=2.2.5 | |
WordPress Frontend Dashboard plugin | <=2.2.5 |
Update the WordPress Frontend Dashboard plugin to the latest available version (at least 2.2.6).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46248 is classified as a high-severity SQL Injection vulnerability that can lead to unauthorized database access.
To fix CVE-2025-46248, upgrade the Frontend Dashboard to version 2.2.6 or later where the vulnerability has been patched.
CVE-2025-46248 affects M A Vinoth Kumar Frontend Dashboard and WordPress Frontend Dashboard versions up to 2.2.5.
Yes, CVE-2025-46248 can be exploited remotely by an attacker to execute arbitrary SQL commands.
Exploitation of CVE-2025-46248 can result in compromised database integrity and unauthorized access to sensitive information.