CVE-2025-48161: WordPress YaySMTP plugin <= 1.3 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows SQL Injection. This issue affects YaySMTP: from n/a through 1.3.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP smtp-sendinblue allows SQL Injection.This issue affects YaySMTP: from n/a through <= 1.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48161?
CVE-2025-48161 is considered a critical SQL Injection vulnerability that can allow attackers to manipulate database queries.
How do I fix CVE-2025-48161?
To fix CVE-2025-48161, update the YaySMTP plugin to version 1.4 or higher.
What versions of YaySMTP are affected by CVE-2025-48161?
CVE-2025-48161 affects YaySMTP versions up to and including 1.3.
What is SQL Injection in the context of CVE-2025-48161?
SQL Injection in CVE-2025-48161 is a vulnerability that allows attackers to inject malicious SQL code into database queries executed by the YaySMTP plugin.
Can CVE-2025-48161 be exploited remotely?
Yes, CVE-2025-48161 can be exploited remotely, allowing attackers to gain unauthorized access to the database.