VYPR
High severity7.5NVD Advisory· Published Oct 15, 2025· Updated Apr 15, 2026

CVE-2025-10743

CVE-2025-10743

Description

The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and including, 1.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Outdoor WordPress plugin (≤1.3.2) has an unauthenticated SQL injection in the 'edit' action, allowing sensitive data extraction.

The Outdoor plugin for WordPress, up to version 1.3.2, contains an SQL injection vulnerability in the 'edit' action. The issue stems from insufficient escaping of user-supplied parameters and lack of proper SQL query preparation, allowing an attacker to inject malicious SQL statements.

An unauthenticated attacker can exploit this vulnerability by sending a crafted request to the 'edit' action with a malicious parameter. No authentication or special privileges are required, making exploitation straightforward for anyone with network access to a vulnerable WordPress site.

Successful exploitation enables attackers to append additional SQL queries to existing database queries, potentially extracting sensitive information from the database, such as usernames, passwords, and other confidential data stored by the WordPress installation.

The plugin has been closed as of October 14, 2025, and is no longer available for download due to this security issue [1]. Users should ensure they are not using any version of this plugin and remove it if present, as no patch is available.

References
  1. Outdoor

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.