CVE-2025-68561: WordPress AutomatorWP plugin <= 5.2.4 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP allows SQL Injection.This issue affects AutomatorWP: from n/a through 5.2.4.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68561?
CVE-2025-68561 is classified as a medium severity SQL Injection vulnerability.
How do I fix CVE-2025-68561?
To fix CVE-2025-68561, update AutomatorWP to version 5.2.5 or later.
What types of attacks can CVE-2025-68561 enable?
CVE-2025-68561 can allow attackers to execute arbitrary SQL queries on the database.
Which versions of AutomatorWP are affected by CVE-2025-68561?
CVE-2025-68561 affects AutomatorWP versions from n/a through 5.2.4.
Is my website vulnerable if I am running AutomatorWP 5.2.4 or earlier?
Yes, if you are running AutomatorWP version 5.2.4 or earlier, your website is vulnerable to CVE-2025-68561.