VYPR
Medium severity6.3OSV Advisory· Published Dec 23, 2024· Updated Apr 15, 2026

CVE-2018-25106

CVE-2018-25106

Description

A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection. The attack may be initiated remotely. The patch is named 41230a81db0f671c570c2644bc2f80565ca83c5a. It is recommended to apply a patch to fix this issue.

Affected products

2
  • Webuidesigning/NebulaxOSV2 versions
    v1.0, v2.0, v3.0, …+ 1 more
    • (no CPE)range: v1.0, v2.0, v3.0, …
    • (no CPE)range: <=5.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.