CVE-2025-58789: WordPress WP Full Stripe Free Plugin <= 8.2.5 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free allows SQL Injection. This issue affects WP Full Stripe Free: from n/a through 8.3.0.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects WP Full Stripe Free: from n/a through <= 8.2.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58789?
The severity of CVE-2025-58789 is considered to be high due to its potential to allow SQL Injection attacks.
How do I fix CVE-2025-58789?
To fix CVE-2025-58789, update the WP Full Stripe Free plugin to a version above 8.3.0.
What versions of WP Full Stripe Free are affected by CVE-2025-58789?
CVE-2025-58789 affects all versions of WP Full Stripe Free from the initial release up to and including 8.3.0.
What type of attack can exploit CVE-2025-58789?
CVE-2025-58789 can be exploited through SQL Injection attacks, which can compromise the database.
Who is the vendor for the affected software in CVE-2025-58789?
The vendor for the affected software in CVE-2025-58789 is Themeisle.