CVE-2025-53256: WordPress YaySMTP plugin <= 2.6.6 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows SQL Injection.This issue affects YaySMTP: from n/a through 2.6.5.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP yaysmtp allows SQL Injection.This issue affects YaySMTP: from n/a through <= 2.6.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53256?
CVE-2025-53256 has a high severity rating due to its potential for allowing SQL Injection attacks.
How do I fix CVE-2025-53256?
To fix CVE-2025-53256, update YaySMTP to version 6.8.2 or later.
What types of software are affected by CVE-2025-53256?
CVE-2025-53256 affects YaySMTP versions up to and including 6.8.1.
Can CVE-2025-53256 lead to data breaches?
Yes, CVE-2025-53256 can lead to data breaches if exploited, as it allows unauthorized data access via SQL Injection.
Is authentication required to exploit CVE-2025-53256?
No, exploitation of CVE-2025-53256 does not require authentication, making it particularly dangerous.