First published: Wed May 07 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail allows SQL Injection. This issue affects Ultimate WP Mail: from n/a through 1.3.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rustaurius Ultimate WP Mail | <=1.3.4 | |
WordPress Ultimate WP Mail | <=1.3.4 |
Update the WordPress Ultimate WP Mail plugin to the latest available version (at least 1.3.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47490 has a high severity due to its potential for SQL injection attacks, compromising database integrity.
To fix CVE-2025-47490, update Rustaurius Ultimate WP Mail to the latest version beyond 1.3.4 where the vulnerability is patched.
If exploited, CVE-2025-47490 can allow attackers to manipulate database queries, potentially leading to data leaks or loss.
CVE-2025-47490 affects all versions of Ultimate WP Mail from its release up to 1.3.4.
CVE-2025-47490 is specific to the Rustaurius and WordPress Ultimate WP Mail plugins.