CVE-2025-58881: WordPress New Simple Gallery Plugin <= 8.0 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery allows Blind SQL Injection. This issue affects New Simple Gallery: from n/a through 8.0.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery new-simple-gallery allows Blind SQL Injection.This issue affects New Simple Gallery: from n/a through <= 8.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58881?
CVE-2025-58881 has been classified as a high-severity SQL Injection vulnerability.
How do I fix CVE-2025-58881?
To fix CVE-2025-58881, upgrade the New Simple Gallery plugin to version 8.1 or later.
What impacts does CVE-2025-58881 have on my site?
CVE-2025-58881 allows for Blind SQL Injection, which could allow attackers to manipulate database queries and potentially extract sensitive data.
Which software versions are affected by CVE-2025-58881?
CVE-2025-58881 affects gopiplus New Simple Gallery and WordPress New Simple Gallery Plugin versions up to and including 8.0.
Can CVE-2025-58881 be exploited remotely?
Yes, CVE-2025-58881 can be exploited remotely if the affected version of the plugin is installed on a publicly accessible site.