CVE-2025-59557: WordPress Learts Addons Plugin < 1.7.5 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts Addons learts-addons allows SQL Injection.This issue affects Learts Addons: from n/a through < 1.7.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59557?
CVE-2025-59557 is considered a high-severity SQL Injection vulnerability that allows attackers to execute arbitrary SQL commands.
How do I fix CVE-2025-59557?
To fix CVE-2025-59557, update the Learts Addons to version 1.7.5 or later.
What products are affected by CVE-2025-59557?
CVE-2025-59557 affects ThemeMove Learts Addons and the WordPress Learts Addons Plugin versions prior to 1.7.5.
What type of vulnerability is CVE-2025-59557?
CVE-2025-59557 is an SQL Injection vulnerability that results from improper neutralization of special elements in SQL commands.
Is CVE-2025-59557 exploitable remotely?
Yes, CVE-2025-59557 is exploitable remotely, allowing attackers to perform SQL Injection attacks through crafted requests.