CVE-2025-48091: WordPress AnyComment plugin <= 0.3.6 - SQL Injection vulnerability
Published Oct 22, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injection.This issue affects AnyComment: from n/a through <= 0.3.6.
Affected Software
2 affected components
Alexander AnyComment<=0.3.6
WordPress AnyComment<=0.3.6
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness