CVE-2025-68550: WordPress WPBulky plugin <= 1.1.13 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky allows Blind SQL Injection.This issue affects WPBulky: from n/a through 1.1.13.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky wpbulky-wp-bulk-edit-post-types allows Blind SQL Injection.This issue affects WPBulky: from n/a through <= 1.1.13.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68550?
CVE-2025-68550 is classified as a high severity vulnerability due to its potential for Blind SQL Injection.
How do I fix CVE-2025-68550?
To fix CVE-2025-68550, update the WPBulky plugin to the latest version beyond 1.1.13.
Which applications are affected by CVE-2025-68550?
CVE-2025-68550 affects the WPBulky plugin for WordPress versions up to and including 1.1.13.
What type of vulnerability is CVE-2025-68550?
CVE-2025-68550 is an SQL Injection vulnerability that can allow attackers to execute unauthorized SQL commands.
Is CVE-2025-68550 exploitative in nature?
Yes, CVE-2025-68550 can be exploited to manipulate database queries and potentially access sensitive information.