CVE-2025-47587: WordPress YaySMTP plugin <= 2.6.4 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP yaysmtp allows Blind SQL Injection.This issue affects YaySMTP: from n/a through <= 2.6.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47587?
The severity of CVE-2025-47587 is classified as high due to the potential for Blind SQL Injection.
How do I fix CVE-2025-47587?
To mitigate CVE-2025-47587, update YaySMTP to version 2.6.5 or later.
What versions of YaySMTP are affected by CVE-2025-47587?
YaySMTP versions from n/a up to and including 2.6.4 are affected by CVE-2025-47587.
What type of vulnerability is CVE-2025-47587?
CVE-2025-47587 is an SQL Injection vulnerability allowing for Blind SQL Injection attacks.
Who is the vendor for the affected software in CVE-2025-47587?
The vendor for the affected software in CVE-2025-47587 is YayCommerce.