CVE-2025-47490: WordPress Ultimate WP Mail plugin <= 1.3.4 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail allows SQL Injection. This issue affects Ultimate WP Mail: from n/a through 1.3.4.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows SQL Injection.This issue affects Ultimate WP Mail: from n/a through <= 1.3.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47490?
CVE-2025-47490 has a high severity due to its potential for SQL injection attacks, compromising database integrity.
How do I fix CVE-2025-47490?
To fix CVE-2025-47490, update Rustaurius Ultimate WP Mail to the latest version beyond 1.3.4 where the vulnerability is patched.
What are the implications of CVE-2025-47490 for my website?
If exploited, CVE-2025-47490 can allow attackers to manipulate database queries, potentially leading to data leaks or loss.
Which versions of Ultimate WP Mail are affected by CVE-2025-47490?
CVE-2025-47490 affects all versions of Ultimate WP Mail from its release up to 1.3.4.
Is CVE-2025-47490 specific to any particular environment?
CVE-2025-47490 is specific to the Rustaurius and WordPress Ultimate WP Mail plugins.