CVE-2025-52822: WordPress WP Roadmap plugin <= 2.1.3 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WP Roadmap allows SQL Injection. This issue affects WP Roadmap: from n/a through 2.1.3.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WP Roadmap wp-roadmap allows SQL Injection.This issue affects WP Roadmap: from n/a through <= 2.1.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52822?
CVE-2025-52822 is classified as a medium severity vulnerability due to its potential for SQL Injection.
How do I fix CVE-2025-52822?
To fix CVE-2025-52822, upgrade the WP Roadmap plugin to version 2.1.4 or later.
What versions of WP Roadmap are affected by CVE-2025-52822?
CVE-2025-52822 affects all WP Roadmap versions from n/a through 2.1.3.
What type of vulnerability is CVE-2025-52822?
CVE-2025-52822 is an SQL Injection vulnerability due to improper neutralization of special elements in SQL commands.
Who is the vendor for the affected software in CVE-2025-52822?
The vendor for the affected software in CVE-2025-52822 is Iqonic Design.